MiniUPnPd through 2.3.11 built with --strict contains a divide-by-zero vulnerability in ProcessSSDPData() that allows unauthenticated local network attackers to crash the daemon. Attackers can send a single multicast M-SEARCH datagram with MX: 0 and a known ST to port 1900, triggering SIGFPE and denying UPnP IGD service.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MiniUPnPd through 2.3.11 built with --strict contains a divide-by-zero vulnerability in ProcessSSDPData() that allows unauthenticated local network attackers to crash the daemon. Attackers can send a single multicast M-SEARCH datagram with MX: 0 and a known ST to port 1900, triggering SIGFPE and denying UPnP IGD service. | |
| Title | MiniUPnPd through 2.3.11 Divide-by-Zero DoS via SSDP M-SEARCH MX Header | |
| First Time appeared |
Miniupnp Project
Miniupnp Project miniupnpd |
|
| Weaknesses | CWE-369 | |
| CPEs | cpe:2.3:a:miniupnp_project:miniupnpd:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Miniupnp Project
Miniupnp Project miniupnpd |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-07T17:43:23.863Z
Reserved: 2026-10-07T10:58:52.326Z
Link: CVE-2026-107159
No data.
Status : Awaiting Analysis
Published: 2026-10-07T12:17:09.283
Modified: 2026-10-07T16:02:27.613
Link: CVE-2026-107159
No data.
OpenCVE Enrichment
Updated: 2026-10-07T13:45:06Z
Weaknesses