Linuxsecurity SUSE Avahi Vulnerabilities Addressed in Recent Updates
Article Content
- •SUSE released patches for two moderate vulnerabilities in Avahi affecting multiple systems.
- •CVE-2026-34933 and CVE-2026-24401 can crash the avahi-daemon under specific conditions.
- •Users should apply the patches using recommended methods to mitigate the risks.
SUSE has released updates addressing two moderate vulnerabilities in the Avahi service, affecting multiple versions of SUSE Linux. The vulnerabilities, identified as CVE-2026-34933 and CVE-2026-24401, can cause the avahi-daemon to crash under specific conditions. CVE-2026-34933 involves a reachable assertion in the `transport_flags_from_domain`, while CVE-2026-24401 deals with unsolicited mDNS responses containing a recursive CNAME record. The updates are applicable to SUSE Linux Enterprise Server 16.0 and SUSE Linux Micro 6.2, among others. Users are advised to apply the patches using SUSE's recommended installation methods. The vulnerabilities were published earlier this year, with CVE-2026-24401 on January 24 and CVE-2026-34933 on April 3. The current status is that patches are available and users are encouraged to update their systems promptly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-24401 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…