AlmaLinux 9.2 [TuxCare] Security Update: avahi / avahi-autoipd / avahi-compat-howl / avahi-compat-howl-devel / etc Multiple Vulnerabilities (ALMALINUX9.2:CLSA-2025:1743675732)

medium Nessus Plugin ID 361906

Synopsis

The AlmaLinux host is missing one or more security updates.

Description

The AlmaLinux 9.2 host has packages installed that are affected by multiple vulnerabilities as referenced in the TuxCare ALMALINUX9.2:CLSA-2025:1743675732 advisory.

- A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.
(CVE-2021-3468)

- A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hostnames. The highest threat from this vulnerability is to the service availability. (CVE-2021-3502)

- A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash. (CVE-2023-1981)

- A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record.
(CVE-2023-38469)

- A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function.
(CVE-2023-38470)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in TuxCare advisory ALMALINUX9.2:CLSA-2025:1743675732.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2025:1743675732

http://www.nessus.org/u?01b39841

Plugin Details

Severity: Medium

ID: 361906

File Name: tuxcare_alma_linux_9.2_CLSA-2025-1743675732.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: Moderate

CVSS v2

Risk Factor: Low

Base Score: 2.1

Temporal Score: 1.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2021-3502

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2023-38473

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/3/2025

Vulnerability Publication Date: 5/7/2021

Reference Information

CVE: CVE-2021-3468, CVE-2021-3502, CVE-2023-1981, CVE-2023-38469, CVE-2023-38470, CVE-2023-38471, CVE-2023-38472, CVE-2023-38473

CLSA: 2025:1743675732