CVE detail
CVE-2021-26720 — CVE-2021-26720
Published 2021-02-17 · Modified 2026-06-17 · Vendor avahi · Product avahi · Source nvd
HIGH
severity
CVSS-derived band
0.0040
EPSS probability
exploitation probability, 30d
32.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE: this only affects the packaging for Debian GNU/Linux (used indirectly by SUSE), not the upstream Avahi product.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References