Logo
vulnerabilityCVE-2021-3468
Name
CVE-2021-3468
Source
NVD ( link)Debian ( link)
Description
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
avahi
Patched

Vulnerability Ratings#


5.5
CVSSv31
2.1
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
0.8
Patched
openwrt
master
0.9_rc4-r1
Not Affected
openwrt
openwrt-25.12
0.9_rc4-r1
Not Affected
yocto
kirkstone
0.8
Exploitable
yocto
master
0.9~rc4
Not Affected
yocto
scarthgap
0.8
Exploitable

Resolved with patches#


avahi (buildroot:2025.02.x)

#
Title
Author
Resolve
1
Avoid infinite-loop in avahi-daemon by handling HUP event in
Riccardo Schirone <sirmy15@gmail.com>
CVE-2021-3468

avahi (buildroot:master)

#
Title
Author
Resolve
1
Avoid infinite-loop in avahi-daemon by handling HUP event in
Riccardo Schirone <sirmy15@gmail.com>
CVE-2021-3468