<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:28:00 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:6707 — Moderate: avahi security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:6707</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: avahi, AlmaLinux:9: avahi-compat-howl, AlmaLinux:9: avahi-compat-howl-devel, AlmaLinux:9: avahi-compat-libdns_sd, AlmaLinux:9: avahi-compat-libdns_sd-devel, AlmaLinux:9: avahi-devel, AlmaLinux:9: avahi-glib, AlmaLinux:9: avahi-glib-devel, AlmaLinux:9: avahi-libs, AlmaLinux:9: avahi-tools&lt;/p&gt;
&lt;p&gt;Avahi is an implementation of the DNS Service Discovery and Multicast DNS specifications for Zero Configuration Networking. It facilitates service discovery on a local network. Avahi and Avahi-aware applications allow you to plug your computer into a network and, with no configuration, view other people to chat with, view printers to print with, and find shared files on other computers.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* avahi: Local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket (CVE-2021-3468)
* avahi: reachable assertion in avahi_s_host_name_resolver_start when trying to resolve badly-formatted hostnames (CVE-2021-3502)
* avahi: avahi-daemon can be crashed via DBus (CVE-2023-1981)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: avahi, AlmaLinux:9: avahi-compat-howl, AlmaLinux:9: avahi-compat-howl-devel, AlmaLinux:9: avahi-compat-libdns_sd, AlmaLinux:9: avahi-compat-libdns_sd-devel, AlmaLinux:9: avahi-devel, AlmaLinux:9: avahi-glib, AlmaLinux:9: avahi-glib-devel, AlmaLinux:9: avahi-libs, AlmaLinux:9: avahi-tools&lt;/p&gt;
&lt;p&gt;Avahi is an implementation of the DNS Service Discovery and Multicast DNS specifications for Zero Configuration Networking. It facilitates service discovery on a local network. Avahi and Avahi-aware applications allow you to plug your computer into a network and, with no configuration, view other people to chat with, view printers to print with, and find shared files on other computers.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* avahi: Local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket (CVE-2021-3468)
* avahi: reachable assertion in avahi_s_host_name_resolver_start when trying to resolve badly-formatted hostnames (CVE-2021-3502)
* avahi: avahi-daemon can be crashed via DBus (CVE-2023-1981)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:6707</guid>
    </item>
    <item>
      <title>bdu:2022-05709</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05709</link>
      <description>bdu:2022-05709</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05709</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-3468 — CVE-2021-3468 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-3468</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-3468</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0969 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</link>
      <description>certfr-2025-avi-0969</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</guid>
    </item>
    <item>
      <title>cnvd-2021-71874</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-71874</link>
      <description>cnvd-2021-71874</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-71874</guid>
    </item>
    <item>
      <title>EUVD-2026-215972</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-215972</link>
      <description>EUVD-2026-215972</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-215972</guid>
    </item>
    <item>
      <title>fkie_cve-2021-3468</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3468</link>
      <description>&lt;p&gt;A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-3468</guid>
    </item>
    <item>
      <title>GHSA-43rm-fv4g-cmj8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-43rm-fv4g-cmj8</link>
      <description>&lt;p&gt;A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-43rm-fv4g-cmj8</guid>
    </item>
    <item>
      <title>gsd-2021-3468</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-3468</link>
      <description>gsd-2021-3468</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-3468</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-3468 — A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-3468</link>
      <description>msrc_CVE-2021-3468</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-3468</guid>
    </item>
    <item>
      <title>OESA-2021-1232 — avahi security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1232</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: avahi&lt;/p&gt;
&lt;p&gt;Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. This enables you to plug your laptop or computer into a network and instantly be able to view other people who you can chat with, find printers to print to or find files being shared.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.(CVE-2021-3468)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: avahi&lt;/p&gt;
&lt;p&gt;Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. This enables you to plug your laptop or computer into a network and instantly be able to view other people who you can chat with, find printers to print to or find files being shared.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.(CVE-2021-3468)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1232</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:0694-1 — Security update for avahi</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0694-1</link>
      <description>&lt;p&gt;Security update for avahi&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for avahi&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:0694-1</guid>
    </item>
    <item>
      <title>RHSA-2024:0418 — Red Hat Security Advisory: avahi security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:0418</link>
      <description>&lt;p&gt;avahi: Local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket avahi: Reachable assertion in avahi_dns_packet_append_record avahi: Reachable assertion in avahi_escape_label avahi: Reachable assertion in dbus_set_host_name avahi: Reachable assertion in avahi_rdata_parse avahi: Reachable assertion in avahi_alternative_host_name&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;avahi: Local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket avahi: Reachable assertion in avahi_dns_packet_append_record avahi: Reachable assertion in avahi_escape_label avahi: Reachable assertion in dbus_set_host_name avahi: Reachable assertion in avahi_rdata_parse avahi: Reachable assertion in avahi_alternative_host_name&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:0418</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:1493-1 — Security update for avahi</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:1493-1</link>
      <description>&lt;p&gt;Security update for avahi&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for avahi&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:1493-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-3468</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3468</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: avahi, Ubuntu:Pro:16.04:LTS: avahi, Ubuntu:18.04:LTS: avahi, Ubuntu:20.04:LTS: avahi&lt;/p&gt;
&lt;p&gt;A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: avahi, Ubuntu:Pro:16.04:LTS: avahi, Ubuntu:18.04:LTS: avahi, Ubuntu:20.04:LTS: avahi&lt;/p&gt;
&lt;p&gt;A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3468</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0143 — avahi: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0143</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in avahi ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in avahi ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0143</guid>
    </item>
  </channel>
</rss>
