CVE-2021-26720: High severity Avahi Avahi vulnerability
avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE: this only affects the packaging for Debian GNU/Linux (used indirectly by SUSE) not the upstream Avahi product.
Other sources
avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE: this only affects the packaging for Debian GNU/Linux (used indirectly by SUSE), not the upstream Avahi product.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/avahito a version that resolves this vulnerability.Fixed in 0.8-5+deb11u2Fixed in 0.8-5+deb11u3Fixed in 0.8-10+deb12u1Fixed in 0.8-16Fixed in 0.8-18 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.8-1
Event History
Frequently Asked Questions
What is CVE-2021-26720?
CVE-2021-26720 is a vulnerability in the avahi package in Debian that allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon.
What is the severity of CVE-2021-26720?
CVE-2021-26720 has a severity value of 7.8 (High).
How does CVE-2021-26720 affect the avahi package?
CVE-2021-26720 affects avahi packages through version 0.8-4.
How can I fix CVE-2021-26720?
To fix CVE-2021-26720, upgrade to avahi package version 0.8-5+deb11u2 or later.
Where can I find more information about CVE-2021-26720?
You can find more information about CVE-2021-26720 on the Openwall website and the Debian security tracker.