Bug 2185911 (CVE-2023-1981) - CVE-2023-1981 avahi: avahi-daemon can be crashed via DBus
Summary: CVE-2023-1981 avahi: avahi-daemon can be crashed via DBus
Keywords:
Status: NEW
Alias: CVE-2023-1981
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2185912 2186688 2186689
Blocks: 2185913
TreeView+ depends on / blocked
 
Reported: 2023-04-11 14:53 UTC by Pedro Sampaio
Modified: 2024-03-19 12:55 UTC (History)
15 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github lathiat avahi issues 375 0 None closed avahi-daemon can be crashed via DBus 2023-04-12 17:26:44 UTC
Github lathiat avahi pull 407 0 None Merged Emit error if Dbus requested service is not found 2023-04-12 17:26:44 UTC
Red Hat Product Errata RHSA-2023:6707 0 None None None 2023-11-07 08:22:45 UTC
Red Hat Product Errata RHSA-2023:7190 0 None None None 2023-11-14 15:22:25 UTC

Description Pedro Sampaio 2023-04-11 14:53:48 UTC
It was discovered that the avahi deamon can be locally crashed by a dbus call made by an unprivileged user, causing a denial of service.

References:

https://github.com/lathiat/avahi/issues/375

Comment 1 Pedro Sampaio 2023-04-11 14:54:04 UTC
Created avahi tracking bugs for this issue:

Affects: fedora-all [bug 2185912]

Comment 6 errata-xmlrpc 2023-11-07 08:22:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2023:6707 https://access.redhat.com/errata/RHSA-2023:6707

Comment 7 errata-xmlrpc 2023-11-14 15:22:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2023:7190 https://access.redhat.com/errata/RHSA-2023:7190


Note You need to log in before you can comment on or make changes to this bug.