{"id":"CVE-2025-68468","summary":"Avahi has a reachable assertion in lookup_multicast_callback","details":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.","aliases":["GHSA-cp79-r4x9-vf52"],"modified":"2026-08-12T15:14:53.164705Z","published":"2026-01-12T17:38:10.492Z","related":["CGA-5xq9-9ffg-5vh9","SUSE-SU-2026:0143-1","SUSE-SU-2026:0259-1","SUSE-SU-2026:0422-1","SUSE-SU-2026:0577-1","SUSE-SU-2026:20145-1","SUSE-SU-2026:20167-1","SUSE-SU-2026:20525-1","SUSE-SU-2026:21445-1","openSUSE-SU-2026:10052-1","openSUSE-SU-2026:20110-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-617"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68468.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68468.json"},{"type":"ADVISORY","url":"https://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68468"},{"type":"REPORT","url":"https://github.com/avahi/avahi/issues/683"},{"type":"FIX","url":"https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/avahi/avahi","events":[{"introduced":"8ee3bd6f7921b489bde14f120187a5becf134d30"},{"fixed":"f66be13d7f31a3ef806d226bf8b67240179d309a"}],"database_specific":{"extracted_events":[{"introduced":"0.9-rc1"},{"last_affected":"0.9-rc1"}],"source":["CPE_STRING","REFERENCES"],"cpe":"cpe:2.3:a:avahi:avahi:0.9:rc1:*:*:*:*:*:*"}}],"versions":["0.9-rc1","v0.9-rc2","v0.9-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68468.json","vanir_signatures_modified":"2026-08-12T15:14:53Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["49796835103246459673476082991326880087","164963310503298087533845724241891385937","142593600093123437609357348851716758755","175781122804758308359834821960804872597"],"threshold":0.9},"id":"CVE-2025-68468-76de3ba8","signature_type":"Line","signature_version":"v1","source":"https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a","target":{"file":"avahi-core/browse.c"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a","target":{"function":"lookup_multicast_callback","file":"avahi-core/browse.c"},"deprecated":false,"digest":{"function_hash":"230147531993436042411123730074032476695","length":1290},"id":"CVE-2025-68468-bf762a75"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}