HomeDefectsLIN1024-14683
Fixed

LIN1024-14683 : Security Advisory - avahi - CVE-2025-68468

Created: Jan 12, 2026    Updated: Jan 26, 2026
Resolved Date: Jan 19, 2026
Found In Version: 10.24.33.2
Fix Version: 10.24.33.15
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Userspace

Description

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.

CVEs