CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-52616: Avahi: avahi wide-area dns predictable transaction ids

Description

A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.

Classification

CVE ID: CVE-2024-52616

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 19.29% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://access.redhat.com/security/cve/CVE-2024-52616
https://bugzilla.redhat.com/show_bug.cgi?id=2326429

Timeline