CVE-2026-49127
8.6MusicPlayerDaemon · MPD
An off-by-one error in the Music Player Daemon (MPD) can lead to service instability and potential security impacts.
Executive summary
A critical off-by-one error in Music Player Daemon (MPD) versions prior to 0.24.11 could allow for remote service disruption.
Vulnerability
This vulnerability involves an Off-by-one Error (CWE-193) which may result in buffer overflows or memory corruption. It is remotely exploitable without authentication, impacting the availability of the daemon.
Business impact
The flaw allows for unauthorized remote disruption of the service, which can cause significant operational downtime for systems relying on MPD. With a CVSS score of 8.6, this vulnerability is highly concerning due to its remote, unauthenticated exploitability, which could be used as a vector for Denial of Service (DoS).
Remediation
Immediate Action: Update the Music Player Daemon (MPD) to version 0.24.11 immediately.
Proactive Monitoring: Monitor the MPD service for frequent or unexplained crashes that may indicate exploitation attempts.
Compensating Controls: Restrict network access to the MPD service using firewalls to ensure it is only accessible from trusted internal network segments.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for remote exploitation and service impact, upgrading to version 0.24.11 is mandatory. Organizations should ensure that all instances of MPD are updated to close this vulnerability and prevent unauthorized service disruption.