[ubuntu/questing-security] avahi 0.8-16ubuntu3.2 (Accepted)

Allen Huang allen.huang at canonical.com
Tue May 12 08:20:21 UTC 2026


avahi (0.8-16ubuntu3.2) questing-security; urgency=medium

  * SECURITY UPDATE: Denial of Service
    - debian/patches/CVE-2026-24401.patch: core: fix uncontrolled
      recursion bug using a simple loop detection algorithm
    - CVE-2026-24401
  * SECURITY UPDATE: Denial of Service
    - debian/patches/CVE-2026-34933-1.patch: core: refuse to accept
      publish flags where both wide_area and multicast are set
    - debian/patches/CVE-2026-34933-2.patch: tests: make sure
      AVAHI_PUBLISH_USE_WIDE_AREA is refused
    - CVE-2026-34933

Date: 2026-05-06 13:47:57.430346+00:00
Changed-By: Allen Huang <allen.huang at canonical.com>
https://launchpad.net/ubuntu/+source/avahi/0.8-16ubuntu3.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Questing-changes mailing list