Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.
{
"cwe_ids": [
"CWE-617"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68471.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68471.json"
[
{
"source": "https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1",
"digest": {
"length": 761.0,
"function_hash": "285681115689231934736972820592826652179"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"target": {
"file": "avahi-core/browse.c",
"function": "lookup_start"
},
"id": "CVE-2025-68471-8b800984"
},
{
"source": "https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1",
"digest": {
"line_hashes": [
"131477049406147028042511519061365218720",
"69024678338108153641727758570983173709",
"91183894014825058501342759438232662511",
"263085132819081757133558578820548525645"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"target": {
"file": "avahi-core/browse.c"
},
"id": "CVE-2025-68471-94d1d7b8"
}
]