Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14461

Опубликовано: 10 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT response used for AS lookups can trigger this bug by returning a DNS response that is larger than 512 bytes and uses a crafted compression pointer in the answer NAME field. ipinfo_lookup() function uses the length of the response as the end-of-message boundary for dn_expand() function. The result is a reliable crash. This issue exists in the mtr through version 0.96 and it was fixed in commit 48e1794414d338ce47abc0f27c25ade8788af9c3.

A flaw was found in mtr. A remote attacker, by influencing the DNS (Domain Name System) TXT response used for AS (Autonomous System) lookups, can trigger an out-of-bound read vulnerability in the ipinfo_lookup() function. This occurs when a DNS response larger than 512 bytes contains a crafted compression pointer in the answer NAME field. Successful exploitation leads to a reliable crash of the mtr application, resulting in a Denial of Service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10mtrFix deferred
Red Hat Enterprise Linux 6mtrOut of support scope
Red Hat Enterprise Linux 7mtrFix deferred
Red Hat Enterprise Linux 8mtrFix deferred
Red Hat Enterprise Linux 9mtrFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-823
https://bugzilla.redhat.com/show_bug.cgi?id=2498972mtr: mtr: Denial of Service via crafted DNS responses

EPSS

Процентиль: 23%
0.00304
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
около 1 месяца назад

mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT response used for AS lookups can trigger this bug by returning a DNS response that is larger than 512 bytes and uses a crafted compression pointer in the answer NAME field. ipinfo_lookup() function uses the length of the response as the end-of-message boundary for dn_expand() function. The result is a reliable crash. This issue exists in the mtr through version 0.96 and it was fixed in commit 48e1794414d338ce47abc0f27c25ade8788af9c3.

nvd
около 1 месяца назад

mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT response used for AS lookups can trigger this bug by returning a DNS response that is larger than 512 bytes and uses a crafted compression pointer in the answer NAME field. ipinfo_lookup() function uses the length of the response as the end-of-message boundary for dn_expand() function. The result is a reliable crash. This issue exists in the mtr through version 0.96 and it was fixed in commit 48e1794414d338ce47abc0f27c25ade8788af9c3.

msrc
около 1 месяца назад

Out-of-bound read in mtr

debian
около 1 месяца назад

mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup( ...

github
около 1 месяца назад

mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT response used for AS lookups can trigger this bug by returning a DNS response that is larger than 512 bytes and uses a crafted compression pointer in the answer NAME field. ipinfo_lookup() function uses the length of the response as the end-of-message boundary for dn_expand() function. The result is a reliable crash. This issue exists in the mtr through version 0.96 and it was fixed in commit 48e1794414d338ce47abc0f27c25ade8788af9c3.

EPSS

Процентиль: 23%
0.00304
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2026-14461