{"id":"CVE-2025-68471","summary":"Avahi has a reachable assertion in lookup_start","details":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.","aliases":["GHSA-56rf-42xr-qmmg"],"modified":"2026-08-12T15:14:52.398652Z","published":"2026-01-12T17:39:57.416Z","related":["CGA-v7jq-4wr6-fgjm","SUSE-SU-2026:0143-1","SUSE-SU-2026:0259-1","SUSE-SU-2026:0422-1","SUSE-SU-2026:0577-1","SUSE-SU-2026:20145-1","SUSE-SU-2026:20167-1","SUSE-SU-2026:20525-1","SUSE-SU-2026:21445-1","openSUSE-SU-2026:10052-1","openSUSE-SU-2026:20110-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-617"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68471.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68471.json"},{"type":"ADVISORY","url":"https://github.com/avahi/avahi/security/advisories/GHSA-56rf-42xr-qmmg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68471"},{"type":"REPORT","url":"https://github.com/avahi/avahi/issues/678"},{"type":"FIX","url":"https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/avahi/avahi","events":[{"introduced":"8ee3bd6f7921b489bde14f120187a5becf134d30"},{"fixed":"9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1"}],"database_specific":{"cpe":"cpe:2.3:a:avahi:avahi:0.9:rc1:*:*:*:*:*:*","extracted_events":[{"introduced":"0.9-rc1"},{"last_affected":"0.9-rc1"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["0.9-rc1","v0.9-rc2","v0.9-rc1"],"database_specific":{"vanir_signatures":[{"digest":{"function_hash":"285681115689231934736972820592826652179","length":761},"id":"CVE-2025-68471-8b800984","signature_type":"Function","signature_version":"v1","source":"https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1","target":{"file":"avahi-core/browse.c","function":"lookup_start"},"deprecated":false},{"id":"CVE-2025-68471-94d1d7b8","signature_type":"Line","signature_version":"v1","source":"https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1","target":{"file":"avahi-core/browse.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["131477049406147028042511519061365218720","69024678338108153641727758570983173709","91183894014825058501342759438232662511","263085132819081757133558578820548525645"]}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68471.json","vanir_signatures_modified":"2026-08-12T15:14:52Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}