Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 512
Alerts This Week
Warning Icon 1 512

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 4 articles for you...
203

Mageia 9 libupnp Important SSRF Port Confusion CVE-2026-41682

Security update. Publication date: 18 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0223.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-41682 Description: Port truncation via atoi() cast in parse_uri() allows SSRF port confusion. (CVE-2026-41682) References: - https://bugs.mageia.org/show_bug.cgi?id=35462 - https://lists.opensuse.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/RGEL3TKVF7UPJUO7JGIIJKNEXLRIV6PS/ - https://github.com/pupnp/pupnp/security/advisories/GHSA-q522-6w45-4j58 - https://www.cve.org/CVERecord?id=CVE-2026-41682 SRPMS: - 9/core/libupnp-1.14.17-1.1.mga9 . Critical Mageia libupnp update addresses SSRF port confusion through atoi() casting error. Protect your system now!. Mageia security advisory, libupnp update, server-side request forgery fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 18, 2026 Important Mageia
203

Mageia: 2021-0319 moderate: libupnp DNS Rebinding Attack

The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server part of pupnp (libupnp) appears to be vulnerable to DNS rebinding attacks because it does not check the value of the 'Host' header. This can be mitigated by using DNS revolvers which block DNS-rebinding attacks. The vulnerability is fixed in version 1.14.6 and later . MGASA-2021-0319 - Updated libupnp packages fix a security vulnerability Publication date: 08 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0319.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-29462 The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server part of pupnp (libupnp) appears to be vulnerable to DNS rebinding attacks because it does not check the value of the 'Host' header. This can be mitigated by using DNS revolvers which block DNS-rebinding attacks. The vulnerability is fixed in version 1.14.6 and later (CVE-2021-29462). References: - https://bugs.mageia.org/show_bug.cgi?id=28923 - https://github.com/pupnp/pupnp/security/advisories/GHSA-6hqq-w3jq-9fhg - https://www.cve.org/CVERecord?id=CVE-2021-29462 SRPMS: - 7/core/libupnp-1.8.4-3.2.mga7 - 8/core/libupnp-1.14.6-1.mga8 . Mageia has released updates for libupnp packages to address a DNS rebinding security flaw, introducing version 1.14.6 and above.. DNS Rebinding Attack, Libupnp Security Fix, Mageia Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 08, 2021 Important Mageia
198

Arch Linux: 202104-8 High Severity: libupnp Content Spoofing Advisory

The package libupnp before version 1.14.6-1 is vulnerable to content spoofing. . Arch Linux Security Advisory ASA-202104-8 ======================================== Severity: High Date : 2021-04-29 CVE-ID : CVE-2021-29462 Package : libupnp Type : content spoofing Remote : Yes Link : https://security.archlinux.org/AVG-1844 Summary ====== The package libupnp before version 1.14.6-1 is vulnerable to content spoofing. Resolution ========= Upgrade to 1.14.6-1. # pacman -Syu "libupnp> =1.14.6-1" The problem has been fixed upstream in version 1.14.6. Workaround ========= None. Description ========== The server part of pupnp (libupnp) appears to be vulnerable to DNS rebinding attacks because it does not check the value of the `Host` header. This can be mitigated by using DNS revolvers which block DNS- rebinding attacks. The vulnerability is fixed in version 1.14.6 and later. Impact ===== An attacker is able to perform a DNS rebinding attack against a client browser to trigger local UPnP services. This can be used to, for example, exfiltrate or tamper data of a client. References ========= https://github.com/pupnp/pupnp/security/advisories/GHSA-6hqq-w3jq-9fhg https://github.com/pupnp/pupnp/commit/21fd85815da7ed2578d0de7cac4c433008f0ecd4 https://security.archlinux.org/CVE-2021-29462 . Arch Linux Security Advisory ASA-202104-8 ======================================== Severity: High Da. package, libupnp, version, vulnerable, content, spoofing, linux, security. . LinuxSecurity.com Team

Calendar%202 Apr 29, 2021 ArchLinux
197

Debian 9 LTS: DLA-2585-1 Moderate: libupnp Denial Of Service

libupnp, the portable SDK for UPnP Devices allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServiceControlURLPath and FindServiceEventURLPath in genlib/service_table/service_table.c. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2585-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta March 08, 2021 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : libupnp Version : 1:1.6.19+git20160116-1.2+deb9u1 CVE ID : CVE-2020-13848 Debian Bug : 962282 libupnp, the portable SDK for UPnP Devices allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServiceControlURLPath and FindServiceEventURLPath in genlib/service_table/service_table.c. For Debian 9 stretch, this problem has been fixed in version 1:1.6.19+git20160116-1.2+deb9u1. We recommend that you upgrade your libupnp packages. For the detailed security status of libupnp please refer to its security tracker page at: Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2586-1 warns of a security vulnerability in libupnp causing potential service disruption. Affected users should update their systems promptly.. libupnp, denial of service, debian advisory, remote access, security update. . LinuxSecurity.com Team

Calendar%202 Mar 07, 2021 Debian LTS
203

Mageia: 2020-0270 Moderate: libupnp Remote Denial of Service Threat

The updated packages fix a security vulnerability: Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions . MGASA-2020-0270 - Updated libupnp packages fix security vulnerability Publication date: 04 Jul 2020 URL: https://advisories.mageia.org/MGASA-2020-0270.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-13848 The updated packages fix a security vulnerability: Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServiceControlURLPath and FindServiceEventURLPath in genlib/service_table/service_table.c. (CVE-2020-13848) References: - https://bugs.mageia.org/show_bug.cgi?id=26752 - https://lists.debian.org/debian-lts-announce/2020/06/msg00006.html - https://www.cve.org/CVERecord?id=CVE-2020-13848 SRPMS: - 7/core/libupnp-1.8.4-3.1.mga7 . Recent libupnp updates address a critical security vulnerability in Mageia. Find out more about the potential dangers associated with remote exploits.. libupnp Security, Mageia Update, Denial of Service, Remote Attack. . LinuxSecurity.com Team

Calendar%202 Jul 04, 2020 Mageia
202

openSUSE Leap 15.1: openSUSE-SU-2020:0805-1 Moderate libupnp DoS

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for libupnp ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0805-1 Rating: moderate References: #1172625 Cross-References: CVE-2020-13848 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libupnp fixes the following issues: - CVE-2020-13848: A NULL ptr denial of service via crafted SSDP message was fixed (boo#1172625) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-805=1 Package List: - openSUSE Leap 15.1 (i586 x86_64): libupnp-debugsource-1.6.25-lp151.3.3.1 libupnp-devel-1.6.25-lp151.3.3.1 libupnp6-1.6.25-lp151.3.3.1 libupnp6-debuginfo-1.6.25-lp151.3.3.1 - openSUSE Leap 15.1 (x86_64): libupnp6-32bit-1.6.25-lp151.3.3.1 libupnp6-32bit-debuginfo-1.6.25-lp151.3.3.1 References: https://www.suse.com/security/cve/CVE-2020-13848.html https://bugzilla.suse.com/1172625 -- . An important patch has been released for openSUSE's libupnp that tackles a moderate denial of service vulnerability. Discover the details of the corrective measures implemented.. openSUSE Update, libupnp Security, Moderate Threat, Denial Of Service. . LinuxSecurity.com Team

Calendar%202 Jun 16, 2020 OpenSUSE
202

openSUSE: 2020:0821-1 Moderate: libupnp Denial of Service Fix

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for libupnp ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0821-1 Rating: moderate References: #1172625 Cross-References: CVE-2020-13848 Affected Products: openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libupnp fixes the following issues: - CVE-2020-13848: A NULL ptr denial of service via crafted SSDP message was fixed (boo#1172625) This update was imported from the openSUSE:Leap:15.1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2020-821=1 Package List: - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): libupnp-devel-1.6.25-bp151.4.3.1 libupnp6-1.6.25-bp151.4.3.1 - openSUSE Backports SLE-15-SP1 (aarch64_ilp32): libupnp6-64bit-1.6.25-bp151.4.3.1 References: https://www.suse.com/security/cve/CVE-2020-13848.html https://bugzilla.suse.com/1172625 -- . This release tackles a medium-risk flaw in libupnp, fixing a null pointer dereference that could lead to a denial of service.. libupnp update, openSUSE Security, moderate vulnerability fix, denial of service, security patch. . LinuxSecurity.com Team

Calendar%202 Jun 16, 2020 OpenSUSE
197

Debian: DLA-2245-1 Important: Security Fix for libxml2 Vulnerability

libupnp, the portable SDK for UPnP Devices allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServiceControlURLPath . Package : libupnp Version : 1.6.19+git20141001-1+deb8u2 CVE ID : CVE-2020-13848 Debian Bug : 962282 libupnp, the portable SDK for UPnP Devices allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServiceControlURLPath and FindServiceEventURLPath in genlib/service_table/service_table.c. This crash can be triggered by sending a malformed SUBSCRIBE or UNSUBSCRIBE using any of the attached files. For Debian 8 "Jessie", this problem has been fixed in version 1.6.19+git20141001-1+deb8u2. We recommend that you upgrade your libupnp packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . libupnp security patch DLA-2238-1 addresses DoS vulnerability on Debian 8, mitigating risks from remote exploitation attempts.. Denial Of Service, libupnp Update, Debian Security, UPnP Services. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 08, 2020 Important Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200