This update for avahi fixes the following issues:
- CVE-2026-34933: reachable assertion in `transport_flags_from_domain` can crash the `avahi-daemon` (bsc#1261546).
- CVE-2026-24401: unsolicited mDNS responses containing a recursive CNAME record can crash the `avahi-daemon`
(bsc#1257235).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1026=1
- openSUSE Leap 16.0:
avahi-0.8-160000.5.1
avahi-autoipd-0.8-160000.5.1
avahi-compat-howl-devel-0.8-160000.5.1
avahi-compat-mDNSResponder-devel-0.8-160000.5.1
avahi-lang-0.8-160000.5.1
avahi-utils-0.8-160000.5.1
avahi-utils-gtk-0.8-160000.5.1
libavahi-client3-0.8-160000.5.1
libavahi-common3-0.8-160000.5.1
libavahi-core7-0.8-160000.5.1
libavahi-devel-0.8-160000.5.1
libavahi-glib-devel-0.8-160000.5.1
libavahi-glib1-0.8-160000.5.1
libavahi-gobject-devel-0.8-160000.5.1
libavahi-gobject0-0.8-160000.5.1
libavahi-libevent1-0.8-160000.5.1
libavahi-qt6-1-0.8-160000.5.1
libavahi-qt6-devel-0.8-160000.5.1
libavahi-ui-gtk3-0-0.8-160000.5.1
libdns_sd-0.8-160000.5.1
libhowl0-0.8-160000.5.1
python3-avahi-gtk-0.8-160000.5.1
python313-avahi-0.8-160000.5.1
typelib-1_0-Avahi-0_6-0.8-160000.5.1
* bsc#1257235
* bsc#1261546
References:
* https://www.suse.com/security/cve/CVE-2026-24401.html
* https://www.suse.com/security/cve/CVE-2026-34933.html
Get the latest Linux and open source security news straight to your inbox.