Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Fedora 41: minidlna Important Stack-Buffer Overflow Fix CVE-2023-47430

fedora
Calendar Grey July 18, 2025
Dist Fedora Esm H88
Important patch applied to minidlna in Fedora 41 addresses potential stack-buffer overflow issue during the process of log rotation.
Avoid restarting minidlna.service when rotating logs if it's not running

Summary

MiniDLNA (aka ReadyDLNA) is server software with the aim of being fully

compliant with DLNA/UPnP-AV clients.

The minidlna daemon serves media files (music, pictures, and video) to clients

on your local network. Example clients include applications such as Totem and

XBMC, and devices such as portable media players, smartphones, and televisions.

Update Information:

Avoid restarting minidlna.service when rotating logs if it's not running. Fix CVE-2023-47430 .

Change Log

* Mon Jul 7 2025 Dominik Mierzejewski - 1.3.3-10 - use systemctl try-restart in postrotate script (resolves rhbz#2372859) - attempt to fix CVE-2023-47430 (resolves rhbz#2271621)

References


[ 1 ] Bug #2271621 - CVE-2023-47430 minidlna: Stack-buffer-overflow vulnerability in ReadyMedia [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2271621 [ 2 ] Bug #2372859 - Use `systemctl try-restart` in logrotate postrotate script https://bugzilla.redhat.com/show_bug.cgi?id=2372859

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-0f490a9a10' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: minidlna
Product: Fedora 41
Version: 1.3.3
Release: 10.fc41
Summary: Lightweight DLNA/UPnP-AV server targeted at embedded systems

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here