Vulnerability record · CVE-2008-5081 · published 17 December 2008
CVE-2008-5081: Avahi daemon assertion failure via crafted mDNS packet causes DoS
Avahi · Avahi
Avahi before 0.6.24 has a flaw in originates_from_local_legacy_unicast_socket in avahi-core/server.c. A crafted mDNS packet with a source port of 0 triggers an assertion failure, crashing avahi-daemon. The daemon is widely deployed for zero-configuration networking, so a crash can disrupt name resolution and service discovery on affected hosts.
Description
The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause a denial of service (crash) via a crafted mDNS packet with a source port of 0, which triggers an assertion failure.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityThe flaw is remotely reachable without authentication and public exploit code exists, but it only causes a denial of service and a fixed version is available.
What it is
Avahi before 0.6.24 has a flaw in originates_from_local_legacy_unicast_socket in avahi-core/server.c. A crafted mDNS packet with a source port of 0 triggers an assertion failure, crashing avahi-daemon. The daemon is widely deployed for zero-configuration networking, so a crash can disrupt name resolution and service discovery on affected hosts.
Impact
An attacker can crash avahi-daemon, causing a denial of service for mDNS/DNS-SD name resolution and service discovery on the host. No confidentiality or integrity impact is described; the CVSS vector shows availability impact only.
Attack surface
Reachable over the network via a crafted mDNS packet, per the AV:N vector and the description. No authentication is required (Au:N), and no user interaction is indicated.
Exploitation
Not listed in CISA KEV and no ransomware association is documented. EPSS is high (0.59223, 99th percentile), and an Exploit-DB entry (7520) is referenced, indicating public exploit code exists.
What to do
- Upgrade Avahi to 0.6.24 or later, or apply the vendor patch for your distribution.
- If Avahi is not needed, disable or remove avahi-daemon to remove the exposure.
- Restrict mDNS (UDP 5353) traffic to trusted network segments where feasible.
- Monitor vendor advisories (Debian, Ubuntu, Gentoo, openSUSE) for updated packages and apply them.
Detection
- Monitor avahi-daemon logs for assertion failures or abnormal crashes.
- Alert on unexpected avahi-daemon process restarts or core dumps.
- Inspect network traffic for mDNS packets with a source port of 0.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-5081 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-5081), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.