CVE-2021-3468
NixOS vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2021-3468) was discovered in Avahi versions 0.6 through 0.8. The flaw exists in the handling of client connection termination events on the Avahi Unix socket within the client_work function. This vulnerability was reported on March 16, 2021, and affects the Avahi service, a framework for Multicast DNS Service Discovery (Debian LTS, Red Hat Bugzilla).

Technical details

The vulnerability stems from multiple issues in the client connection handling: 1) The client_work() function always expects a newline in the buffer and won't process data until one is found, 2) There's no check to ensure connection interruption when the input buffer is full without a newline, 3) The AVAHI_WATCH_HUP event, which signals connection termination, is not handled in client_work() function, and 4) The AVAHI_WATCH_IN event is disabled when the input buffer becomes full. The vulnerability has been assigned a CVSS v3.1 Base Score of 5.5 (Medium) with vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

The primary impact of this vulnerability is on service availability. When exploited, it causes the Avahi daemon to enter an infinite loop, making the service unresponsive. This creates a denial of service condition that affects the availability of the Avahi service (Red Hat Bugzilla).

Exploitability

The vulnerability can be triggered by a local attacker by writing long lines to /run/avahi-daemon/socket. The exploit requires local access to the system and can be triggered by filling the input buffer and then terminating the connection, causing the daemon to enter an infinite loop (Red Hat Bugzilla).

Mitigation and workarounds

The vulnerability has been patched in various distributions. Debian has released fixes in version 0.6.32-2+deb9u1 for Stretch, 0.7-4+deb10u3 for Buster, and Red Hat has addressed this in multiple releases through security updates RHSA-2023:6707, RHSA-2023:7836, RHSA-2024:0418, and RHSA-2024:0576 (Debian LTS, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2025-49506HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management