INFSA-2025:7437: avahi security update

Information about definition

Identificator: INFSA-2025:7437

Type: security

Release date: 2025-06-10 08:47:01 UTC

Information about package

Avahi is an implementation of the DNS Service Discovery and Multicast DNS specifications for Zero Configuration Networking. It facilitates service discovery on a local network. Avahi and Avahi-aware applications allow you to plug your computer into a network and, with no configuration, view other people to chat with, view printers to print with, and find shared files on other computers.

Vulnerabilities description

  • CVE-2024-52616

    A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 5.3 no information
Critical, important, moderate, low

Updated packages