DEBIAN-CVE-2026-48045

Source
https://security-tracker.debian.org/tracker/CVE-2026-48045
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-48045.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-48045
Upstream
Published
2026-07-17T19:17:15Z
Modified
2026-09-14T17:03:16Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.12, AsyncListener.handle_query_or_defer retained every truncated TC-bit incoming query, each up to _MAX_MSG_ABSOLUTE = 8966 bytes, in self._deferred[addr] and armed a per-address timer in self._timers[addr] without capping the per-address list or distinct addr keys, allowing unauthenticated hosts on the local link over UDP/5353 (224.0.0.251 / ff02::fb) to spoof sources, grow _deferred and _timers, and cause memory exhaustion and quadratic CPU burn. This issue is fixed in version 0.149.12.

References

Affected packages

Debian:12 / python-zeroconf

Package

Name
python-zeroconf
Purl
pkg:deb/debian/python-zeroconf?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.47.3-1
0.47.4-1
0.53.0-1
0.54.0-1
0.56.0-1
0.58.0-1
0.58.2-1
0.62.0-1
0.63.0-1
0.64.1-1
0.66.0-1
0.69.0-1
0.70.0-1
0.71.0-1
0.71.4-1
0.74.0-1
0.74.0-2
0.76.0-1
0.80.0-1
0.82.1-1
0.88.0-1
0.91.1-1
0.97.0-1
0.102.0-1
0.108.0-1
0.111.0-1
0.112.0-1
0.115.0-1
0.115.1-1
0.115.2-1
0.118.0-1
0.119.0-1
0.120.0-1
0.122.2-1
0.122.3-1
0.123.0-1
0.125.0-1
0.126.0-1
0.127.0-1
0.128.0-1
0.128.0-2
0.128.4-1
0.129.0-1
0.130.0-1
0.131.0-1
0.132.0-1
0.132.2-1
0.132.2-2
0.133.0-1
0.134.0-1
0.135.0-1
0.136.0-1
0.136.2-1
0.139.0-1
0.139.0-2
0.139.0-3
0.139.0-4
0.140.1-1
0.141.0-1
0.143.0-1
0.144.3-1
0.145.1-1
0.145.1-2
0.146.1-1
0.146.3-1
0.146.5-1
0.147.0-1
0.147.0-2
0.147.2-1
0.147.2-2
0.148.0-1
0.148.0-2
0.148.0-3
0.148.0-4
0.149.6-1
0.149.7-1
0.149.9-1
0.149.16-1
0.150.0-1
0.150.0-2
0.151.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-48045.json"

Debian:13 / python-zeroconf

Package

Name
python-zeroconf
Purl
pkg:deb/debian/python-zeroconf?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.147.0-1
0.147.0-2
0.147.2-1
0.147.2-2
0.148.0-1
0.148.0-2
0.148.0-3
0.148.0-4
0.149.6-1
0.149.7-1
0.149.9-1
0.149.16-1
0.150.0-1
0.150.0-2
0.151.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-48045.json"

Debian:14 / python-zeroconf

Package

Name
python-zeroconf
Purl
pkg:deb/debian/python-zeroconf?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.149.16-1

Affected versions

0.*
0.147.0-1
0.147.0-2
0.147.2-1
0.147.2-2
0.148.0-1
0.148.0-2
0.148.0-3
0.148.0-4
0.149.6-1
0.149.7-1
0.149.9-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-48045.json"