Critical Integer Underflow Vulnerability in MiniUPnPd Affects Ubuntu Systems

Critical Integer Underflow Vulnerability in MiniUPnPd Affects Ubuntu Systems

First seen 7 Sep 2026, 13:06 UTC UbuntuLinuxsecurity 45.0

Article Content

Browse articles
ThreatCluster

A significant integer underflow vulnerability has been identified in MiniUPnPd, affecting Ubuntu systems. This flaw allows remote attackers to exploit specially crafted SOAPAction headers to cause a denial of service or disclose sensitive information. The vulnerability is linked to the parsing of SOAPAction headers, where a single quote can trigger the issue. Systems running various versions of Ubuntu, including 20.04 LTS to 26.04 LTS, are impacted. Users are advised to update their systems to the latest package versions to mitigate the risk. The vulnerability has been assigned the identifier USN-8731-1. A standard system update will apply the necessary patches. The issue was disclosed on September 7, 2026, with no active exploitation reported yet.

Key Points: • MiniUPnPd vulnerability allows remote denial of service or information disclosure. • Affected Ubuntu versions include 20.04 LTS to 26.04 LTS. • Users should update to the latest package versions to mitigate risks.

Ask AI about this cluster

Timeline

2026-09-07
Vulnerability disclosed
An integer underflow vulnerability in MiniUPnPd was publicly disclosed, impacting multiple Ubuntu LTS versions.
Linuxsecurity
2026-09-07
Patch available
Ubuntu has released updates for affected MiniUPnPd versions to address the vulnerability.
Ubuntu