#1144393 mrtg: CVE-2026-72694

Package:
src:mrtg
Source:
src:mrtg
Submitter:
Moritz Mühlenhoff
Date:
2026-09-05 15:49:02 UTC
Severity:
normal
Tags:
#1144393#5
Date:
2026-08-14 15:04:14 UTC
From:
To:
Hi,

The following vulnerability was published for mrtg.

CVE-2026-72694[0]:
| A flaw was found in MRTG. When the MRTG daemon is started as a root
| user and subsequently drops privileges, a local, low-privileged
| attacker can exploit a symbolic link (symlink) following
| vulnerability. By influencing or pre-placing a symlink in the
| process ID (PID) file path, the attacker can trick the root process
| into changing the ownership of an arbitrary existing file to the
| daemon user. This can lead to local privilege escalation, allowing
| unauthorized access to or modification of sensitive files.

https://bugzilla.redhat.com/show_bug.cgi?id=2460973
Fixed by: https://github.com/oetiker/mrtg/commit/30e19216bfadc0148f347cb0a42fd5e2016e6269


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-72694
https://www.cve.org/CVERecord?id=CVE-2026-72694

Please adjust the affected versions in the BTS as needed.

#1144393#12
Date:
2026-08-18 01:06:02 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
mrtg, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144393@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Joao Eriberto Mota Filho <eriberto@debian.org> (supplier of updated mrtg package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 17 Aug 2026 20:48:14 -0300
Source: mrtg
Architecture: source
Version: 2.17.10-15
Distribution: unstable
Urgency: medium
Maintainer: Joao Eriberto Mota Filho <eriberto@debian.org>
Changed-By: Joao Eriberto Mota Filho <eriberto@debian.org>
Closes: 1144393
Changes:
 mrtg (2.17.10-15) unstable; urgency=medium
 .
   * debian/control:
       - Bumped compat level to 14.
       - Bumped Standards-Version to 4.7.4.
       - Removed no longer needed "Priority: optional" field.
   * debian/copyright:
       - Converted the last paragraph of the GPL-2+ in a comment.
       - Updated packaging copyright years.
   * debian/patches/110_fix-CVE-2026-72694: created to fix a symlink-following
     chown of pid file in daemon mode. Thanks to Tobias Oetiker
     <tobi@oetiker.ch>. This patch fixes CVE-2026-72694. (Closes: #1144393)
   * debian/watch: migrated to version 5.
Checksums-Sha1:
 6a0155695d97e96831976a95161c67610f3e2ba6 1958 mrtg_2.17.10-15.dsc
 6ddf350af04f31f0e2127867bc11dde2678db540 44204 mrtg_2.17.10-15.debian.tar.xz
 00af2e0b961e71477e113c0cdd89f13d795229aa 8500 mrtg_2.17.10-15_source.buildinfo
Checksums-Sha256:
 129c065dd65db52f4ad70582acd1f7895cd251938ca36d3187b858a020832974 1958 mrtg_2.17.10-15.dsc
 fcb8545dae1f49459ba22e2861a36f2fc2680eda2f6017d5eeb38d4a97a53d89 44204 mrtg_2.17.10-15.debian.tar.xz
 e72902f234ec392539c357664557773acf5ad9722cac9313cd56968ecc589148 8500 mrtg_2.17.10-15_source.buildinfo
Files:
 abc028150e09b22b215601c024bc9e28 1958 net optional mrtg_2.17.10-15.dsc
 3ce84da465489f16a3cbfea2b37afb38 44204 net optional mrtg_2.17.10-15.debian.tar.xz
 19b6e9257f329a16c638ae32e1f3a123 8500 net optional mrtg_2.17.10-15_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEENX3LDuyVoBrrofDS3mO5xwTr6e8FAmqDqyUACgkQ3mO5xwTr
6e9sOA//TwPLx4s9YKjMzr3RQGz9wM9ggaciXhVzkB7W6ynempnoqWY/r4gNYPg6
jOrHaMzNalDhXSR1lHv9PppsznIeZhhfS9gth3qj2PoO1YR9B2iAYYIpaoBR6DJ3
wo/OgwzidIW7F/XRXcMW5eOwjmxk+3GwhdCVBX4tt5H+RGYuuice1gS8ICerqcRV
o8lgjNUDUWxGXTfmdgogJ4VFh10o0aunKmJ2ptVao74g1eijhmcFQrTgrrglsb9z
aPZq8ZeH+ynKjcwJSJ6vby1wYlRUmmJhKNj5uOQhCK+6nsiTnSi4ATZWdf0dilMD
6pXr4pSFcKwD8qMeqrzs8I6RCWRYvlol9JglL69nxOLcvDd4CQ1B9yLgz5klLt+D
mF4XJZj6IjQeNzGSG4JxLV3HaCKWsMcwpqsUzhaCQXaOFVj+MWLCqx70nn+8X6dp
ReCdeVOtzPfrMRmZOXMQ7juE3GQkKYyjhgLLduMZdST7Z86MaotoZHPQZfHrgOyp
XnFGV7RT6P1w3OMjhrECISxR6csEgUe5+axOao2AjCcftgzdz/o9poEZDH05I9uM
kUTCIdM1H+8JmQs8SkYQVA3JAoc1dihj/iFlLB/377/FkdHzKdJYfxvoSzUDVyxk
vQqqp9R3MxeMWcIJno08zx2A/8nPuBGtSHJ4Kt1UUEMUL/kYbGo=
=/kOc
-----END PGP SIGNATURE-----

#1144393#17
Date:
2026-09-05 15:47:07 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
mrtg, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144393@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Joao Eriberto Mota Filho <eriberto@debian.org> (supplier of updated mrtg package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 18 Aug 2026 14:00:34 -0300
Source: mrtg
Binary: mrtg mrtg-contrib mrtg-dbgsym
Architecture: source all amd64
Version: 2.17.10-13+deb13u2
Distribution: trixie
Urgency: medium
Maintainer: Joao Eriberto Mota Filho <eriberto@debian.org>
Changed-By: Joao Eriberto Mota Filho <eriberto@debian.org>
Description:
 mrtg       - Multi Router Traffic Grapher
 mrtg-contrib - Multi Router Traffic Grapher (contributed files)
Closes: 1144393
Changes:
 mrtg (2.17.10-13+deb13u2) trixie; urgency=medium
 .
   * debian/patches/110_fix-CVE-2026-72694: created to fix a symlink-following
     chown of pid file in daemon mode. Thanks to Tobias Oetiker
     <tobi@oetiker.ch>. This patch fixes CVE-2026-72694. (Closes: #1144393)
Checksums-Sha1:
 8f8efd88fcab40570ae5d9b1acec1aa1963b004f 1990 mrtg_2.17.10-13+deb13u2.dsc
 133293f060b3567b561fdf4790624b76c90ffb17 44132 mrtg_2.17.10-13+deb13u2.debian.tar.xz
 5b664afb41dc36f64deb824886f6dcf6380719c3 389656 mrtg-contrib_2.17.10-13+deb13u2_all.deb
 d31e0fe1e797ba63d60c7df2e6e79fee76d60ebe 40480 mrtg-dbgsym_2.17.10-13+deb13u2_amd64.deb
 87c21a797c21e06dfafb0804afbc1a5332baea23 8890 mrtg_2.17.10-13+deb13u2_amd64.buildinfo
 7f79e6ed2abb46e3c44f7c38c5f9c309b98b100d 392048 mrtg_2.17.10-13+deb13u2_amd64.deb
Checksums-Sha256:
 80c278874e4996eb139478749b30258ed3d25df590f65df200714595bc2f0570 1990 mrtg_2.17.10-13+deb13u2.dsc
 33275a1cdda36b4c0361a00061575c0e4e3e0cfb5dda66771cd0a7e168a2bef0 44132 mrtg_2.17.10-13+deb13u2.debian.tar.xz
 b83c074e8c4e6d70f82886ebab3908fbb3f4a67d73c64a063cb81ce4d979ad75 389656 mrtg-contrib_2.17.10-13+deb13u2_all.deb
 fe73d06b2803dffa45a7ab7a8b1515d3c319a44b4b62c45e0b5ab8c8e093d28c 40480 mrtg-dbgsym_2.17.10-13+deb13u2_amd64.deb
 74276aac1ea9e5529fb158f3a12620379344a8625fdb60c70ea665ff2298ca53 8890 mrtg_2.17.10-13+deb13u2_amd64.buildinfo
 e87be174f5d02f751fb5a90ceb6f600ee7caa915db49602c0a4dcc5e56bbaf84 392048 mrtg_2.17.10-13+deb13u2_amd64.deb
Files:
 93e806591584141dfbbeec760e4da1c2 1990 net optional mrtg_2.17.10-13+deb13u2.dsc
 2a25e4c66a37eb5d95c75c069f783ee0 44132 net optional mrtg_2.17.10-13+deb13u2.debian.tar.xz
 d5dfecd7d46ae37c095a4b1d4cc2eca5 389656 net optional mrtg-contrib_2.17.10-13+deb13u2_all.deb
 804c117ea0a0b5f636d123f32e98964a 40480 debug optional mrtg-dbgsym_2.17.10-13+deb13u2_amd64.deb
 138418cb050e7bda6848d427e404268f 8890 net optional mrtg_2.17.10-13+deb13u2_amd64.buildinfo
 e65a7c32980ff7bea7eddd54666c2cae 392048 net optional mrtg_2.17.10-13+deb13u2_amd64.deb
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEENX3LDuyVoBrrofDS3mO5xwTr6e8FAmqEskoACgkQ3mO5xwTr
6e+gNA//ZHSgcYQ1Vq7GP9C9D7LMbgc/jv0chl2TfS3HOjQLJ4mCTJT+ejousmfo
lG12K+Z3EMGN1myOloFMTCZnlTrPUSB+C7yCg1NUNyoA1zkR7ONlyf24wohZI9R4
O5bZ7n3V19x7oHhYarhA1YHwUu0mhF39gCKpei0cJ415SgEiq95ixih7kr/MF4jg
4FW0ZmYUxFMEC2SSyy8kKW6WvIiPES5aA05OunpM1/rS01HfeB+CIxVEsx+XuAsr
lt+7RMHCRUpiE3nANCn0jxJXqpUHea/4weLzIWRILHerukn3g9FUFF7Am0pZaqfH
D+XxODQfB7GbvKtbiyUyzAQ9D5VwZX7Lc1VRn7Fr3nleuVYsr0wwUd/59xJfeIAD
VEcgipzMXYPmuDHhwhEfyyVYyvwJayQf9D7Y5BIh6LYfa0qMYSfK3ZKYvJnuXKtQ
HRGUuTeE/VTMEjPUERVru/4Y0F7o3Zrx1aL17DjNj/6DOE59YZKNL0xwtMN0LyMP
NxCPeQsi97Bj1cibLIndLCKAhGH6CfESxKEIjfcxh8m3c+M+ABRQugW//enuNQpT
RXrZdW6l25pvrKgikJx4bxKyWiZlWweP9NKPPbUI865Cjpkch8ueNEX9cviZx89O
Acy7/e+bXgHnztiVxSzPrJJmFmEOIwcS1vDw6UXQRwdPxn8/WB8=
=2WCE
-----END PGP SIGNATURE-----