Hi, The following vulnerability was published for mtr. CVE-2026-14461[0]: | mtr is vulnerable to Out-of-bound read vulnerability in | ipinfo_lookup() function. An attacker who can influence the TXT | response used for AS lookups can trigger this bug by returning a DNS | response that is larger than 512 bytes and uses a crafted | compression pointer in the answer NAME field. ipinfo_lookup() | function uses the length of the response as the end-of-message | boundary for dn_expand() function. The result is a reliable crash. | This issue exists in the mtr through version 0.96 and it was fixed | in commit 48e1794414d338ce47abc0f27c25ade8788af9c3. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-14461 https://www.cve.org/CVERecord?id=CVE-2026-14461 [1] https://github.com/traviscross/mtr/commit/48e1794414d338ce47abc0f27c25ade8788af9c3 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
I was in correspondence with the person who found it (Micha~ Majchrowicz). He suggested a 3 line fix, I argued that one of those would be enough according to the manuals of the functions involved. He agreed. The patch is in current-git. When this all happened, there may already have been an CVE assigned by CERT-PL, and maybe not. I don't remember the exact timeline. OK. I looked it up. Patch is tagged by git as june 16th, Cert mailed with the assigned CVE on july 7th. So it is physically impossible for me to retroactively tag the patch commit 48e1794414d338ce47abc0f27c25ade8788af9c3 with the CVE. I don't think it is a big deal. An attacker would have to force a victim to run mtr to a target, while specifying a specific option and controlling the name servers of part of the route. (easy to do as a security researcher because you can inject whatever you want in your local DNS setup) When those conditions are met, the attacker can crash the unprivileged part of mtr (proven). Unproven is if this can be leveraged to a RCE but the preconditions make this a tricky/risky attack vector. (I think it is almost always possible that a crash is leveraged into RCE. This is a "better safe than sorry".) Roger.
I was in correspondence with the person who found it (Micha~ Majchrowicz). He suggested a 3 line fix, I argued that one of those would be enough according to the manuals of the functions involved. He agreed. The patch is in current-git. When this all happened, there may already have been an CVE assigned by CERT-PL, and maybe not. I don't remember the exact timeline. OK. I looked it up. Patch is tagged by git as june 16th, Cert mailed with the assigned CVE on july 7th. So it is physically impossible for me to retroactively tag the patch commit 48e1794414d338ce47abc0f27c25ade8788af9c3 with the CVE. I don't think it is a big deal. An attacker would have to force a victim to run mtr to a target, while specifying a specific option and controlling the name servers of part of the route. (easy to do as a security researcher because you can inject whatever you want in your local DNS setup) When those conditions are met, the attacker can crash the unprivileged part of mtr (proven). Unproven is if this can be leveraged to a RCE but the preconditions make this a tricky/risky attack vector. (I think it is almost always possible that a crash is leveraged into RCE. This is a "better safe than sorry".) Roger.
We believe that the bug you reported is fixed in the latest version of
mtr, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1143069@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Robert Woodcock <rcw@debian.org> (supplier of updated mtr package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 02 Aug 2026 21:50:31 -0700
Source: mtr
Binary: mtr mtr-dbgsym mtr-tiny mtr-tiny-dbgsym
Architecture: source amd64
Version: 0.96-2
Distribution: unstable
Urgency: high
Maintainer: Robert Woodcock <rcw@debian.org>
Changed-By: Robert Woodcock <rcw@debian.org>
Description:
mtr - Full screen ncurses and X11 traceroute tool
mtr-tiny - Full screen ncurses traceroute tool
Closes: 1143069
Changes:
mtr (0.96-2) unstable; urgency=high
.
* Include patch from Micha Majchrowicz and Rogier Wolff to
limit length of ASN DNS responses to address CVE-2026-14461
(closes: #1143069)
Checksums-Sha1:
3884b9f7174a42678c5a22005c0e4faa6ed14429 1939 mtr_0.96-2.dsc
f1e210bb59dcc57b22cd646d799dcf7ea2096bdc 8520 mtr_0.96-2.debian.tar.xz
1e8ae22de2a0e92a6ef94e4658bc32e49f20db43 159728 mtr-dbgsym_0.96-2_amd64.deb
c2f68e48a2e6afca1f504ce3e067b6160b55a9f4 139376 mtr-tiny-dbgsym_0.96-2_amd64.deb
397f22ab7f30c439ea17ababf7bb85a7157d1d7a 71484 mtr-tiny_0.96-2_amd64.deb
ba8ded879902653cd8dc58fe281a082b09237e81 16370 mtr_0.96-2_amd64.buildinfo
97eee659a7c2e47698cf701fbcb2b446c417ca98 87648 mtr_0.96-2_amd64.deb
Checksums-Sha256:
0a4724d69d1493f852421f0aa5bdc94b8464f19d76963edffb988f088c2c9bff 1939 mtr_0.96-2.dsc
14f45ae95c61791bbd90bbc5adfcce52686494a555f673207425709fb63ee06c 8520 mtr_0.96-2.debian.tar.xz
467338b9bc63db7a304b45c2aacb7607a4e90f0cd0b01f5334ba92ce887a0f40 159728 mtr-dbgsym_0.96-2_amd64.deb
a356456be5b57364749695b2e85b01594e38d7a5022485585a2d216855e7fda7 139376 mtr-tiny-dbgsym_0.96-2_amd64.deb
e76f66a015143d38762d1adaa9c95be5738432b8349087c11ccb1db76b14b7cb 71484 mtr-tiny_0.96-2_amd64.deb
b90c754d79c989136178f0a9f7eb1132b331b0f3db812ec5b6054994ff015c74 16370 mtr_0.96-2_amd64.buildinfo
cdbbe3634b0d35db4c6c76dc61b68df3929f8aed44bd7eab9d436325b9f43b6d 87648 mtr_0.96-2_amd64.deb
Files:
83c48fb5ec8e10228d2f2877f7e7c20e 1939 net optional mtr_0.96-2.dsc
b6bcd010204fbc232ffda9c27982a514 8520 net optional mtr_0.96-2.debian.tar.xz
3dbd792794897cb523f8101be11a8f8f 159728 debug optional mtr-dbgsym_0.96-2_amd64.deb
30f16f57e2fb65df4b73c5c6ed1eb7ec 139376 debug optional mtr-tiny-dbgsym_0.96-2_amd64.deb
e40efcd4adedbbd46880c1d5146354a0 71484 net optional mtr-tiny_0.96-2_amd64.deb
be269f6dd14244cb26c2a72526a3eaad 16370 net optional mtr_0.96-2_amd64.buildinfo
244c2e7cfa2d9c58c6324e07737f9034 87648 net optional mtr_0.96-2_amd64.deb
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEYfaVo0u263Atw/XBgpyhlC8G2SUFAmpwpoMACgkQgpyhlC8G
2SXQaw/+MnYcHhxHFVb2cVVF61TiEEFx2TbpoVXnNUsfSBZZHEjB8PSi0OBNv2ZC
EI1Z8OD70Y7nHt4gU77Yv26wpWdp4P9tjmEdYABBBN0FcYZyQlBK+LruWz6VgHzG
q9ywMLEHyFsrOIJnfJQucFOOa3gnmBSR/eIt9iLSHKCiVAo0AKiBuNnWrD+X1Trd
g18E/AbyT0/8XU5msCJXs9gMznsrT8piEXE20jjWifgq+KZj+BRRWwcXNzwEC6b9
WPvmZpOVponYcxuOGgo8i6e297Mpg5/URSrzpGFQyMM6oyQyKm105wLvYssdS9js
2vR1tgFvBz7ICY81bmQJJuSTMbfEEjA32YyRka+exX/52WeaS/8Jn9bY45XPqs9p
spN5I3I5QGuhnine6X3qRxHkaxCNoy/rpJXzSV5IMPWPIHHsIcLqZPMvQIxOC/wz
QhyKiDmo8/4wJ9lUgxbW20RlhWVurUnzBZHV+LSZGe5SKbZ7xu8mzJa4havSI3N7
n9QO5W0c5kAyBe0K09Z+2eeQOxImsyqkMdGOl1scW0tVy2T24XqS1UsG4Dn/ks8u
ylkdHMtREPH4mrqMqY9ORQ61s2mxOe02WOfwc+Zqa7lv155PxG7CxAvkhHLYJ9jz
Ou3XDOwemn3IDoZKBKrWWGayft0X4t/3BPn4pwKiBgFIq5VrS6o=
=CeqO
-----END PGP SIGNATURE-----