
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2021-3468) was discovered in Avahi versions 0.6 through 0.8. The flaw exists in the handling of client connection termination events on the Avahi Unix socket within the client_work function. This vulnerability was reported on March 16, 2021, and affects the Avahi service, a framework for Multicast DNS Service Discovery (Debian LTS, Red Hat Bugzilla).
The vulnerability stems from multiple issues in the client connection handling: 1) The client_work() function always expects a newline in the buffer and won't process data until one is found, 2) There's no check to ensure connection interruption when the input buffer is full without a newline, 3) The AVAHI_WATCH_HUP event, which signals connection termination, is not handled in client_work() function, and 4) The AVAHI_WATCH_IN event is disabled when the input buffer becomes full. The vulnerability has been assigned a CVSS v3.1 Base Score of 5.5 (Medium) with vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).
The primary impact of this vulnerability is on service availability. When exploited, it causes the Avahi daemon to enter an infinite loop, making the service unresponsive. This creates a denial of service condition that affects the availability of the Avahi service (Red Hat Bugzilla).
The vulnerability can be triggered by a local attacker by writing long lines to /run/avahi-daemon/socket. The exploit requires local access to the system and can be triggered by filling the input buffer and then terminating the connection, causing the daemon to enter an infinite loop (Red Hat Bugzilla).
The vulnerability has been patched in various distributions. Debian has released fixes in version 0.6.32-2+deb9u1 for Stretch, 0.7-4+deb10u3 for Buster, and Red Hat has addressed this in multiple releases through security updates RHSA-2023:6707, RHSA-2023:7836, RHSA-2024:0418, and RHSA-2024:0576 (Debian LTS, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."