Out-of-bounds read in PUPnP - #VU152874
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to read adjacent heap memory.
The vulnerability exists due to an out-of-bounds read in GetClientSubActualSID when handling crafted GENA NOTIFY SID headers. A remote attacker can send a GENA NOTIFY request containing an oversized SID header to read adjacent heap memory.
A control point must hold an active subscription to the attacker's device.