Vulnerability Description
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Avahi | Avahi | < 0.9 |
Related Weaknesses (CWE)
References
- https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309aPatch
- https://github.com/avahi/avahi/issues/683Issue TrackingPatch
- https://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52Vendor Advisory
FAQ
What is CVE-2025-68468?
CVE-2025-68468 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements co...
How severe is CVE-2025-68468?
CVE-2025-68468 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-68468?
Check the references section above for vendor advisories and patch information. Affected products include: Avahi Avahi.