{"id":"openSUSE-SU-2026:21175-1","summary":"Security update for python-zeroconf","details":"This update for python-zeroconf fixes the following issues:\n\nChanges in python-zeroconf:\n\n- CVE-2026-47180: zeroconf has unbounded recursion in DNS\n  compression-pointer decoder that allows LAN-local denial of service\n  (bsc#1268341)\n- CVE-2026-47183: zeroconf: Unbounded exception-dedup state retains\n  packet buffers via traceback frame locals, enabling LAN-local memory\n  exhaustion (bsc#1268342)\n- CVE-2026-47184: zeroconf has unbounded DNS record cache that allows\n  LAN-local memory exhaustion via multicast flood (bsc#1268343)\n- CVE-2026-48045: python-zeroconf: Unbounded TC-deferred queue allows\n  LAN-local memory exhaustion via spoofed-source flood (bsc#1268388)\n- CVE-2026-48487: python-zeroconf: Unvalidated rdlength in record\n  payload readers allows LAN-local cache corruption via crafted mDNS\n  packet (bsc#1268235)\n","modified":"2026-07-02T18:24:18.074320160Z","published":"2026-06-30T09:08:26Z","related":["CVE-2026-47180","CVE-2026-47183","CVE-2026-47184","CVE-2026-48045","CVE-2026-48487"],"upstream":["CVE-2026-47180","CVE-2026-47183","CVE-2026-47184","CVE-2026-48045","CVE-2026-48487"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268235"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268341"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268342"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268343"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268388"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47180"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47183"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47184"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48045"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48487"}],"affected":[{"package":{"name":"python-zeroconf","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/python-zeroconf&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.136.0-bp160.2.1"}]}],"ecosystem_specific":{"binaries":[{"python313-zeroconf":"0.136.0-bp160.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21175-1.json"}}],"schema_version":"1.7.5"}