{"id":"CVE-2025-68468","summary":"Avahi has a reachable assertion in lookup_multicast_callback","details":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.","aliases":["GHSA-cp79-r4x9-vf52"],"modified":"2026-08-18T17:54:19.030394Z","published":"2026-01-12T17:38:10.492Z","related":["SUSE-SU-2026:0143-1","SUSE-SU-2026:0259-1","SUSE-SU-2026:0422-1","SUSE-SU-2026:0577-1","SUSE-SU-2026:20145-1","SUSE-SU-2026:20167-1","SUSE-SU-2026:20525-1","SUSE-SU-2026:21445-1","openSUSE-SU-2026:10052-1","openSUSE-SU-2026:20110-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-617"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68468.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68468.json"},{"type":"ADVISORY","url":"https://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68468"},{"type":"REPORT","url":"https://github.com/avahi/avahi/issues/683"},{"type":"FIX","url":"https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/avahi/avahi","events":[{"introduced":"8ee3bd6f7921b489bde14f120187a5becf134d30"},{"fixed":"f66be13d7f31a3ef806d226bf8b67240179d309a"}],"database_specific":{"cpe":"cpe:2.3:a:avahi:avahi:0.9:rc1:*:*:*:*:*:*","extracted_events":[{"introduced":"0.9-rc1"},{"last_affected":"0.9-rc1"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["0.9-rc1","v0.9-rc2","v0.9-rc1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68468.json","vanir_signatures_modified":"2026-08-18T17:54:19Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a","target":{"file":"avahi-core/browse.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["49796835103246459673476082991326880087","164963310503298087533845724241891385937","142593600093123437609357348851716758755","175781122804758308359834821960804872597"]},"id":"CVE-2025-68468-76de3ba8"},{"id":"CVE-2025-68468-bf762a75","signature_type":"Function","signature_version":"v1","source":"https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a","target":{"file":"avahi-core/browse.c","function":"lookup_multicast_callback"},"deprecated":false,"digest":{"function_hash":"230147531993436042411123730074032476695","length":1290}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}