Executive brief
Avahi is a widely used system service that allows devices like printers and computers to discover each other on a local network. A vulnerability has been identified where a local user on a computer can intentionally crash this service by sending a specifically crafted request. While this does not allow for data theft, it disables network discovery features (like AirPlay or printer sharing) and can cause persistent service outages on the affected machine.
Technical details
A reachable assertion exists in the transport_flags_from_domain() function within Avahi's entry.c. The vulnerability is triggered when an unprivileged local user invokes D-Bus methods (such as AddService or AddRecord) on the org.freedesktop.Avahi.EntryGroup interface while passing both the AVAHI_PUBLISH_USE_MULTICAST (0x100) and AVAHI_PUBLISH_USE_WIDE_AREA (0x80) flags simultaneously. While the initial validation macro (AVAHI_FLAGS_VALID) permits both bits, the underlying transport function uses an assert() to enforce their mutual exclusivity. This results in a SIGABRT and daemon crash. The issue is fixed in version 0.9-rc4 by explicitly refusing requests containing both flags.
Affected products
- Avahi Avahi <= 0.8, 0.9-rc1, 0.9-rc2, 0.9-rc3
Timeline
- 2026-03-10: disclosed: Vulnerability discovered by Orange Cyberdefense
- 2026-04-01: patched: Fix merged in GitHub pull request #891
- 2026-04-01: advisory: GitHub Security Advisory GHSA-w65r-6gxh-vhvc published
- 2026-04-03: advisory: CVE-2026-34933 published to NVD