Your message dated Mon, 03 Aug 2026 17:05:41 +0000
with message-id <[email protected]>
and subject line Bug#1143069: fixed in mtr 0.96-2
has caused the Debian Bug report #1143069,
regarding mtr: CVE-2026-14461
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1143069: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143069
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: mtr
Version: 0.96-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for mtr.
CVE-2026-14461[0]:
| mtr is vulnerable to Out-of-bound read vulnerability in
| ipinfo_lookup() function. An attacker who can influence the TXT
| response used for AS lookups can trigger this bug by returning a DNS
| response that is larger than 512 bytes and uses a crafted
| compression pointer in the answer NAME field. ipinfo_lookup()
| function uses the length of the response as the end-of-message
| boundary for dn_expand() function. The result is a reliable crash.
| This issue exists in the mtr through version 0.96 and it was fixed
| in commit 48e1794414d338ce47abc0f27c25ade8788af9c3.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-14461
https://www.cve.org/CVERecord?id=CVE-2026-14461
[1]
https://github.com/traviscross/mtr/commit/48e1794414d338ce47abc0f27c25ade8788af9c3
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: mtr
Source-Version: 0.96-2
Done: Robert Woodcock <[email protected]>
We believe that the bug you reported is fixed in the latest version of
mtr, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Robert Woodcock <[email protected]> (supplier of updated mtr package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 02 Aug 2026 21:50:31 -0700
Source: mtr
Binary: mtr mtr-dbgsym mtr-tiny mtr-tiny-dbgsym
Architecture: source amd64
Version: 0.96-2
Distribution: unstable
Urgency: high
Maintainer: Robert Woodcock <[email protected]>
Changed-By: Robert Woodcock <[email protected]>
Description:
mtr - Full screen ncurses and X11 traceroute tool
mtr-tiny - Full screen ncurses traceroute tool
Closes: 1143069
Changes:
mtr (0.96-2) unstable; urgency=high
.
* Include patch from Micha Majchrowicz and Rogier Wolff to
limit length of ASN DNS responses to address CVE-2026-14461
(closes: #1143069)
Checksums-Sha1:
3884b9f7174a42678c5a22005c0e4faa6ed14429 1939 mtr_0.96-2.dsc
f1e210bb59dcc57b22cd646d799dcf7ea2096bdc 8520 mtr_0.96-2.debian.tar.xz
1e8ae22de2a0e92a6ef94e4658bc32e49f20db43 159728 mtr-dbgsym_0.96-2_amd64.deb
c2f68e48a2e6afca1f504ce3e067b6160b55a9f4 139376
mtr-tiny-dbgsym_0.96-2_amd64.deb
397f22ab7f30c439ea17ababf7bb85a7157d1d7a 71484 mtr-tiny_0.96-2_amd64.deb
ba8ded879902653cd8dc58fe281a082b09237e81 16370 mtr_0.96-2_amd64.buildinfo
97eee659a7c2e47698cf701fbcb2b446c417ca98 87648 mtr_0.96-2_amd64.deb
Checksums-Sha256:
0a4724d69d1493f852421f0aa5bdc94b8464f19d76963edffb988f088c2c9bff 1939
mtr_0.96-2.dsc
14f45ae95c61791bbd90bbc5adfcce52686494a555f673207425709fb63ee06c 8520
mtr_0.96-2.debian.tar.xz
467338b9bc63db7a304b45c2aacb7607a4e90f0cd0b01f5334ba92ce887a0f40 159728
mtr-dbgsym_0.96-2_amd64.deb
a356456be5b57364749695b2e85b01594e38d7a5022485585a2d216855e7fda7 139376
mtr-tiny-dbgsym_0.96-2_amd64.deb
e76f66a015143d38762d1adaa9c95be5738432b8349087c11ccb1db76b14b7cb 71484
mtr-tiny_0.96-2_amd64.deb
b90c754d79c989136178f0a9f7eb1132b331b0f3db812ec5b6054994ff015c74 16370
mtr_0.96-2_amd64.buildinfo
cdbbe3634b0d35db4c6c76dc61b68df3929f8aed44bd7eab9d436325b9f43b6d 87648
mtr_0.96-2_amd64.deb
Files:
83c48fb5ec8e10228d2f2877f7e7c20e 1939 net optional mtr_0.96-2.dsc
b6bcd010204fbc232ffda9c27982a514 8520 net optional mtr_0.96-2.debian.tar.xz
3dbd792794897cb523f8101be11a8f8f 159728 debug optional
mtr-dbgsym_0.96-2_amd64.deb
30f16f57e2fb65df4b73c5c6ed1eb7ec 139376 debug optional
mtr-tiny-dbgsym_0.96-2_amd64.deb
e40efcd4adedbbd46880c1d5146354a0 71484 net optional mtr-tiny_0.96-2_amd64.deb
be269f6dd14244cb26c2a72526a3eaad 16370 net optional mtr_0.96-2_amd64.buildinfo
244c2e7cfa2d9c58c6324e07737f9034 87648 net optional mtr_0.96-2_amd64.deb
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEYfaVo0u263Atw/XBgpyhlC8G2SUFAmpwpoMACgkQgpyhlC8G
2SXQaw/+MnYcHhxHFVb2cVVF61TiEEFx2TbpoVXnNUsfSBZZHEjB8PSi0OBNv2ZC
EI1Z8OD70Y7nHt4gU77Yv26wpWdp4P9tjmEdYABBBN0FcYZyQlBK+LruWz6VgHzG
q9ywMLEHyFsrOIJnfJQucFOOa3gnmBSR/eIt9iLSHKCiVAo0AKiBuNnWrD+X1Trd
g18E/AbyT0/8XU5msCJXs9gMznsrT8piEXE20jjWifgq+KZj+BRRWwcXNzwEC6b9
WPvmZpOVponYcxuOGgo8i6e297Mpg5/URSrzpGFQyMM6oyQyKm105wLvYssdS9js
2vR1tgFvBz7ICY81bmQJJuSTMbfEEjA32YyRka+exX/52WeaS/8Jn9bY45XPqs9p
spN5I3I5QGuhnine6X3qRxHkaxCNoy/rpJXzSV5IMPWPIHHsIcLqZPMvQIxOC/wz
QhyKiDmo8/4wJ9lUgxbW20RlhWVurUnzBZHV+LSZGe5SKbZ7xu8mzJa4havSI3N7
n9QO5W0c5kAyBe0K09Z+2eeQOxImsyqkMdGOl1scW0tVy2T24XqS1UsG4Dn/ks8u
ylkdHMtREPH4mrqMqY9ORQ61s2mxOe02WOfwc+Zqa7lv155PxG7CxAvkhHLYJ9jz
Ou3XDOwemn3IDoZKBKrWWGayft0X4t/3BPn4pwKiBgFIq5VrS6o=
=CeqO
-----END PGP SIGNATURE-----
pgp9ao6ZKiT3c.pgp
Description: PGP signature
--- End Message ---