CVE-2025-59529 is a denial-of-service vulnerability affecting Avahi versions up to and including 0.9-rc2. The Avahi simple protocol server fails to enforce its documented client limit, allowing an unlimited number of connections. This flaw enables unprivileged local users to exhaust daemon memory and file descriptors, leading to a system-wide denial of service for mDNS/DNS-SD. Rated with a CVSS score of 5.5 (MEDIUM), the vulnerability has a local attack vector with low attack complexity, resulting in high availability impact. There is no known impact on confidentiality or integrity. As of the time of publication, there are no known patched versions, and no active exploitation or public exploit code has been identified. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9CPE matchmatch criteria | cpe:2.3:a:avahi:avahi:*:*:*:*:*:*:*:* | ||
0.9CPE matchmatch criteria | cpe:2.3:a:avahi:avahi:0.9:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.