← Vulnerability feed

Vulnerability record · CVE-2008-5081 · published 17 December 2008

CVE-2008-5081: Avahi daemon assertion failure via crafted mDNS packet causes DoS

Avahi · Avahi

Avahi before 0.6.24 has a flaw in originates_from_local_legacy_unicast_socket in avahi-core/server.c. A crafted mDNS packet with a source port of 0 triggers an assertion failure, crashing avahi-daemon. The daemon is widely deployed for zero-configuration networking, so a crash can disrupt name resolution and service discovery on affected hosts.

5.0 CVSS 2.0 Medium EPSS 59% · top 0.9% CWE-399 · CWE-399
5.0CVSS 2.0 base score
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
26References
16 Jun 2026Last modified by NVD

Description

The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause a denial of service (crash) via a crafted mDNS packet with a source port of 0, which triggers an assertion failure.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

medium priorityThe flaw is remotely reachable without authentication and public exploit code exists, but it only causes a denial of service and a fixed version is available.

What it is

Avahi before 0.6.24 has a flaw in originates_from_local_legacy_unicast_socket in avahi-core/server.c. A crafted mDNS packet with a source port of 0 triggers an assertion failure, crashing avahi-daemon. The daemon is widely deployed for zero-configuration networking, so a crash can disrupt name resolution and service discovery on affected hosts.

Impact

An attacker can crash avahi-daemon, causing a denial of service for mDNS/DNS-SD name resolution and service discovery on the host. No confidentiality or integrity impact is described; the CVSS vector shows availability impact only.

Attack surface

Reachable over the network via a crafted mDNS packet, per the AV:N vector and the description. No authentication is required (Au:N), and no user interaction is indicated.

Exploitation

Not listed in CISA KEV and no ransomware association is documented. EPSS is high (0.59223, 99th percentile), and an Exploit-DB entry (7520) is referenced, indicating public exploit code exists.

What to do

  • Upgrade Avahi to 0.6.24 or later, or apply the vendor patch for your distribution.
  • If Avahi is not needed, disable or remove avahi-daemon to remove the exposure.
  • Restrict mDNS (UDP 5353) traffic to trusted network segments where feasible.
  • Monitor vendor advisories (Debian, Ubuntu, Gentoo, openSUSE) for updated packages and apply them.

Detection

  • Monitor avahi-daemon logs for assertion failures or abnormal crashes.
  • Alert on unexpected avahi-daemon process restarts or core dumps.
  • Inspect network traffic for mDNS packets with a source port of 0.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-5081 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2017-6519Avahi origin validation error vulnerabilityavahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows …EPSS 3.2%7.8CVE-2021-26720Avahi link following vulnerabilityavahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local att…EPSS 0.40%6.5CVE-2026-24401Avahi vulnerabilityAvahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daem…EPSS 0.30%6.5CVE-2025-68468Avahi vulnerabilityAvahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can…EPSS 0.39%6.5CVE-2025-68471Avahi vulnerabilityAvahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can…EPSS 0.41%5.5CVE-2026-34933Avahi vulnerabilityAvahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileg…EPSS 0.16%5.5CVE-2025-68276Avahi vulnerabilityAvahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged …EPSS 0.16%5.5CVE-2025-59529Avahi uncontrolled resource consumption vulnerabilityAvahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2,…EPSS 0.18%

Source: NIST National Vulnerability Database (record CVE-2008-5081), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.