DEBIAN-CVE-2026-47183

Source
https://security-tracker.debian.org/tracker/CVE-2026-47183
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-47183.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-47183
Upstream
Published
2026-07-17T19:17:15Z
Modified
2026-09-14T17:03:16Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.6, DNSIncoming._log_exception_debug and the four QuietLogger exception-dedup methods stored an unbounded _seen_logs dictionary keyed by attacker-influenced IncomingDecodeError messages, retaining sys.exc_info() tracebacks whose frame locals kept raw packet self.data buffers and allowing unauthenticated hosts on the local link over UDP/5353 (224.0.0.251 / ff02::fb) to drive memory growth until mDNS-dependent features degrade or the process is OOM-killed. This issue is fixed in version 0.149.6.

References

Affected packages

Debian:12 / python-zeroconf

Package

Name
python-zeroconf
Purl
pkg:deb/debian/python-zeroconf?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.47.3-1
0.47.4-1
0.53.0-1
0.54.0-1
0.56.0-1
0.58.0-1
0.58.2-1
0.62.0-1
0.63.0-1
0.64.1-1
0.66.0-1
0.69.0-1
0.70.0-1
0.71.0-1
0.71.4-1
0.74.0-1
0.74.0-2
0.76.0-1
0.80.0-1
0.82.1-1
0.88.0-1
0.91.1-1
0.97.0-1
0.102.0-1
0.108.0-1
0.111.0-1
0.112.0-1
0.115.0-1
0.115.1-1
0.115.2-1
0.118.0-1
0.119.0-1
0.120.0-1
0.122.2-1
0.122.3-1
0.123.0-1
0.125.0-1
0.126.0-1
0.127.0-1
0.128.0-1
0.128.0-2
0.128.4-1
0.129.0-1
0.130.0-1
0.131.0-1
0.132.0-1
0.132.2-1
0.132.2-2
0.133.0-1
0.134.0-1
0.135.0-1
0.136.0-1
0.136.2-1
0.139.0-1
0.139.0-2
0.139.0-3
0.139.0-4
0.140.1-1
0.141.0-1
0.143.0-1
0.144.3-1
0.145.1-1
0.145.1-2
0.146.1-1
0.146.3-1
0.146.5-1
0.147.0-1
0.147.0-2
0.147.2-1
0.147.2-2
0.148.0-1
0.148.0-2
0.148.0-3
0.148.0-4
0.149.6-1
0.149.7-1
0.149.9-1
0.149.16-1
0.150.0-1
0.150.0-2
0.151.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-47183.json"

Debian:13 / python-zeroconf

Package

Name
python-zeroconf
Purl
pkg:deb/debian/python-zeroconf?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.147.0-1
0.147.0-2
0.147.2-1
0.147.2-2
0.148.0-1
0.148.0-2
0.148.0-3
0.148.0-4
0.149.6-1
0.149.7-1
0.149.9-1
0.149.16-1
0.150.0-1
0.150.0-2
0.151.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-47183.json"

Debian:14 / python-zeroconf

Package

Name
python-zeroconf
Purl
pkg:deb/debian/python-zeroconf?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.149.6-1

Affected versions

0.*
0.147.0-1
0.147.0-2
0.147.2-1
0.147.2-2
0.148.0-1
0.148.0-2
0.148.0-3
0.148.0-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-47183.json"