I was in correspondence with the person who found it (Micha~
Majchrowicz). He suggested a 3 line fix, I argued that one of those
would be enough according to the manuals of the functions involved. He
agreed.
The patch is in current-git.
When this all happened, there may already have been an CVE assigned by
CERT-PL, and maybe not. I don't remember the exact timeline.
OK. I looked it up. Patch is tagged by git as june 16th, Cert mailed
with the assigned CVE on july 7th.
So it is physically impossible for me to retroactively tag the patch
commit 48e1794414d338ce47abc0f27c25ade8788af9c3
with the CVE.
I don't think it is a big deal. An attacker would have to force a
victim to run mtr to a target, while specifying a specific option and
controlling the name servers of part of the route. (easy to do as a
security researcher because you can inject whatever you want in your
local DNS setup)
When those
conditions are met, the attacker can crash the unprivileged part of
mtr (proven). Unproven is if this can be leveraged to a RCE but the
preconditions make this a tricky/risky attack vector. (I think it is
almost always possible that a crash is leveraged into RCE. This is
a "better safe than sorry".)
Roger.
On Thu, Jul 30, 2026 at 07:27:16AM +0200, Salvatore Bonaccorso wrote:
> Source: mtr
> Version: 0.96-1
> Severity: important
> Tags: security upstream
> X-Debbugs-Cc: [email protected], Debian Security Team
> <[email protected]>
>
> Hi,
>
> The following vulnerability was published for mtr.
>
> CVE-2026-14461[0]:
> | mtr is vulnerable to Out-of-bound read vulnerability in
> | ipinfo_lookup() function. An attacker who can influence the TXT
> | response used for AS lookups can trigger this bug by returning a DNS
> | response that is larger than 512 bytes and uses a crafted
> | compression pointer in the answer NAME field. ipinfo_lookup()
> | function uses the length of the response as the end-of-message
> | boundary for dn_expand() function. The result is a reliable crash.
> | This issue exists in the mtr through version 0.96 and it was fixed
> | in commit 48e1794414d338ce47abc0f27c25ade8788af9c3.
>
>
> If you fix the vulnerability please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
>
> For further information see:
>
> [0] https://security-tracker.debian.org/tracker/CVE-2026-14461
> https://www.cve.org/CVERecord?id=CVE-2026-14461
> [1]
> https://github.com/traviscross/mtr/commit/48e1794414d338ce47abc0f27c25ade8788af9c3
>
> Please adjust the affected versions in the BTS as needed.
>
> Regards,
> Salvatore
--
** [email protected] ** https://www.BitWizard.nl/ ** +31-15-2049110 **
** Verl. Spiegelmakerstraat 37 2645 LZ Delfgauw, The Netherlands.
** KVK: 27239233 **
f equals m times a. When your f is steady, and your m is going down
your a** is going up. -- Chris Hadfield about flying up the space shuttle.
** 'a' for accelleration.