Alerts This Week
Warning Icon 1 625
Alerts This Week
Warning Icon 1 625

Mageia 9 libupnp Important SSRF Port Confusion CVE-2026-41682

mageia
Calendar Grey June 18, 2026
Dist Mageia Esm H88
Critical Mageia libupnp update addresses SSRF port confusion through atoi() casting error. Protect your system now!
Security update

Summary

Description: Port truncation via atoi() cast in parse_uri() allows SSRF port confusion. (CVE-2026-41682)

References

- https://bugs.mageia.org/show_bug.cgi?id=35462

- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/RGEL3TKVF7UPJUO7JGIIJKNEXLRIV6PS/

- https://github.com/pupnp/pupnp/security/advisories/GHSA-q522-6w45-4j58

- https://www.cve.org/CVERecord?id=CVE-2026-41682

Resolution

SRPMS

- 9/core/libupnp-1.14.17-1.1.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 18 Jun 2026 
URL: https://advisories.mageia.org/MGASA-2026-0223.html
Type: security
CVE: CVE-2026-41682

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here