From f715bbf5a4de2c4c1914548a657894f57a0a6881 Mon Sep 17 00:00:00 2001 From: Samuel Dionne-Riel Date: Tue, 7 Apr 2026 18:08:08 -0400 Subject: [PATCH] nixos/avahi: Warn when susceptible to CVE-2024-52615 --- nixos/modules/services/networking/avahi-daemon.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/nixos/modules/services/networking/avahi-daemon.nix b/nixos/modules/services/networking/avahi-daemon.nix index 55a90649ba43..b01b4b3b0eb8 100644 --- a/nixos/modules/services/networking/avahi-daemon.nix +++ b/nixos/modules/services/networking/avahi-daemon.nix @@ -283,6 +283,10 @@ in }; config = lib.mkIf cfg.enable { + warnings = [ + (lib.mkIf cfg.wideArea "Enabling `services.avahi.wideArea` exposes this system to `CVE-2024-52615`.") + ]; + users.users.avahi = { description = "avahi-daemon privilege separation user"; home = "/var/empty";