CVE-2024-52615: Red Hat Enterprise Linux 10
Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.
A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.
Affected products
- Red Hat Red Hat Enterprise Linux 10: before 0:0.9~rc2-1.el10_0.1 (fixed in 0:0.9~rc2-1.el10_0.1)
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9: before 0:0.8-22.el9_6.1 (fixed in 0:0.8-22.el9_6.1)
- Red Hat Red Hat Openshift Container Platform 4
Published 2024-11-21. Last modified 2026-06-29.