UBUNTU-CVE-2026-5720
Dashboard / Vulnerabilities / UBUNTU-CVE-2026-5720
UBUNTU-CVE-2026-5720
Summary:
Details: miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attackers can trigger an out-of-bounds memory read by exploiting improper length validation in ParseHttpHeaders(), where the parsed length underflows to a large unsigned value when passed to memchr(), causing the process to scan memory far beyond the allocated HTTP request buffer.
References: https://ubuntu.com/security/CVE-2026-5720, https://www.cve.org/CVERecord?id=CVE-2026-5720, https://ubuntu.com/security/notices/USN-8731-1
Affected packages
Package
Name: miniupnpd
Purl: pkg:deb/ubuntu/miniupnpd?arch=source&distro=esm-apps-legacy%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
