openSUSE-SU-2026:21175-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21175-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21175-1
Upstream
Related
Published
2026-06-30T09:08:26Z
Modified
2026-07-02T18:24:18Z
Summary
Security update for python-zeroconf
Details

This update for python-zeroconf fixes the following issues:

Changes in python-zeroconf:

  • CVE-2026-47180: zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of service (bsc#1268341)
  • CVE-2026-47183: zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion (bsc#1268342)
  • CVE-2026-47184: zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood (bsc#1268343)
  • CVE-2026-48045: python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood (bsc#1268388)
  • CVE-2026-48487: python-zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet (bsc#1268235)
References

Affected packages

openSUSE:Leap 16.0 / python-zeroconf

Package

Name
python-zeroconf
Purl
pkg:rpm/opensuse/python-zeroconf&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.136.0-bp160.2.1

Ecosystem specific

{
    "binaries": [
        {
            "python313-zeroconf": "0.136.0-bp160.2.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21175-1.json"