{"id":"CVE-2025-68276","summary":"Avahi has a reachable assertion in avahi_wide_area_scan_cache","details":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can be done by either calling\nthe RecordBrowserNew method directly or creating hostname/address/service resolvers/browsers that create those browsers internally themselves.","aliases":["GHSA-mhf3-865v-g5rc"],"modified":"2026-08-12T03:51:32.322996283Z","published":"2026-01-12T17:31:49.652Z","related":["CGA-jmg5-4hh5-6c46","SUSE-SU-2026:0143-1","SUSE-SU-2026:0259-1","SUSE-SU-2026:0422-1","SUSE-SU-2026:0577-1","SUSE-SU-2026:20145-1","SUSE-SU-2026:20167-1","SUSE-SU-2026:20525-1","SUSE-SU-2026:21445-1","openSUSE-SU-2026:10052-1","openSUSE-SU-2026:20110-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-617"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68276.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68276.json"},{"type":"ADVISORY","url":"https://github.com/avahi/avahi/security/advisories/GHSA-mhf3-865v-g5rc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68276"},{"type":"FIX","url":"https://github.com/avahi/avahi/commit/ede7048475c5d47d53890e3bc1350dda8e0b3688"},{"type":"FIX","url":"https://github.com/avahi/avahi/pull/806"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/avahi/avahi","events":[{"introduced":"8ee3bd6f7921b489bde14f120187a5becf134d30"},{"fixed":"ede7048475c5d47d53890e3bc1350dda8e0b3688"}],"database_specific":{"source":["CPE_STRING","REFERENCES"],"cpe":"cpe:2.3:a:avahi:avahi:0.9:rc1:*:*:*:*:*:*","extracted_events":[{"introduced":"0.9-rc1"},{"last_affected":"0.9-rc1"}]}}],"versions":["0.9-rc1","v0.9-rc2","v0.9-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68276.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}