{"id":"DEBIAN-CVE-2026-48045","details":"Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.12, AsyncListener.handle_query_or_defer retained every truncated TC-bit incoming query, each up to _MAX_MSG_ABSOLUTE = 8966 bytes, in self._deferred[addr] and armed a per-address timer in self._timers[addr] without capping the per-address list or distinct addr keys, allowing unauthenticated hosts on the local link over UDP/5353 (224.0.0.251 / ff02::fb) to spoof sources, grow _deferred and _timers, and cause memory exhaustion and quadratic CPU burn. This issue is fixed in version 0.149.12.","modified":"2026-09-14T17:03:16.144482721Z","published":"2026-07-17T19:17:15.820Z","upstream":["CVE-2026-48045"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-48045"}],"affected":[{"package":{"name":"python-zeroconf","ecosystem":"Debian:12","purl":"pkg:deb/debian/python-zeroconf?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.102.0-1","0.108.0-1","0.111.0-1","0.112.0-1","0.115.0-1","0.115.1-1","0.115.2-1","0.118.0-1","0.119.0-1","0.120.0-1","0.122.2-1","0.122.3-1","0.123.0-1","0.125.0-1","0.126.0-1","0.127.0-1","0.128.0-1","0.128.0-2","0.128.4-1","0.129.0-1","0.130.0-1","0.131.0-1","0.132.0-1","0.132.2-1","0.132.2-2","0.133.0-1","0.134.0-1","0.135.0-1","0.136.0-1","0.136.2-1","0.139.0-1","0.139.0-2","0.139.0-3","0.139.0-4","0.140.1-1","0.141.0-1","0.143.0-1","0.144.3-1","0.145.1-1","0.145.1-2","0.146.1-1","0.146.3-1","0.146.5-1","0.147.0-1","0.147.0-2","0.147.2-1","0.147.2-2","0.148.0-1","0.148.0-2","0.148.0-3","0.148.0-4","0.149.16-1","0.149.6-1","0.149.7-1","0.149.9-1","0.150.0-1","0.150.0-2","0.151.3-1","0.47.3-1","0.47.4-1","0.53.0-1","0.54.0-1","0.56.0-1","0.58.0-1","0.58.2-1","0.62.0-1","0.63.0-1","0.64.1-1","0.66.0-1","0.69.0-1","0.70.0-1","0.71.0-1","0.71.4-1","0.74.0-1","0.74.0-2","0.76.0-1","0.80.0-1","0.82.1-1","0.88.0-1","0.91.1-1","0.97.0-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-48045.json"}},{"package":{"name":"python-zeroconf","ecosystem":"Debian:13","purl":"pkg:deb/debian/python-zeroconf?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.147.0-1","0.147.0-2","0.147.2-1","0.147.2-2","0.148.0-1","0.148.0-2","0.148.0-3","0.148.0-4","0.149.16-1","0.149.6-1","0.149.7-1","0.149.9-1","0.150.0-1","0.150.0-2","0.151.3-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-48045.json"}},{"package":{"name":"python-zeroconf","ecosystem":"Debian:14","purl":"pkg:deb/debian/python-zeroconf?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.149.16-1"}]}],"versions":["0.147.0-1","0.147.0-2","0.147.2-1","0.147.2-2","0.148.0-1","0.148.0-2","0.148.0-3","0.148.0-4","0.149.6-1","0.149.7-1","0.149.9-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-48045.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}