PT-2024-35401 · Unknown+6 · Avahi-Daemon+6

Published

2024-11-15

·

Updated

2026-02-09

·

CVE-2024-52616

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Avahi-daemon (affected versions not specified)
Description A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

ALSA-2025:7437
AZL-53579
AZL-53756
BDU:2026-03600
CLEANSTART-2026-MB75553
CVE-2024-52616
ECHO-78A2-DC43-2A07
INFSA-2025_7437
MGASA-2025-0007
OESA-2025-2251
OPENSUSE-SU-2024:14538-1
OPENSUSE-SU-2024_4196-1
OPENSUSE-SU-2024_4386-1
RHSA-2025:7437
RHSA-2025_7437
SUSE-SU-2024:4196-1
SUSE-SU-2024:4225-1
SUSE-SU-2024:4282-1
SUSE-SU-2024:4386-1
SUSE-SU-2024_4196-1
SUSE-SU-2024_4282-1
SUSE-SU-2024_4386-1
SUSE-SU-2025:20103-1
SUSE-SU-2025:20308-1

Affected Products

Almalinux
Avahi-Daemon
Debian
Red Hat
Red Os
Rocky Linux
Suse