CVE-2026-24401 is a medium-severity vulnerability affecting Avahi versions 0.9rc2 and below, a system for local network service discovery. An attacker can trigger a segmentation fault and crash the avahi-daemon by sending a specially crafted, unsolicited mDNS response containing a recursive CNAME record. This leads to unbounded recursion and stack exhaustion in the lookup_handle_cname function. The vulnerability has a CVSS score of 6.5, indicating a network-based attack with low complexity, requiring no privileges, and resulting in high availability impact (denial of service). User interaction is required for the attack to succeed. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9CPE matchmatch criteria | cpe:2.3:a:avahi:avahi:*:*:*:*:*:*:*:* | ||
0.9CPE matchmatch criteria | cpe:2.3:a:avahi:avahi:0.9:rc1:*:*:*:*:*:* | ||
0.9CPE matchmatch criteria | cpe:2.3:a:avahi:avahi:0.9:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.