UBUNTU-CVE-2026-14461
The mtr utility is affected by an out-of-bound read vulnerability in the ipinfo_lookup() function. This flaw can be triggered by an attacker who controls the TXT DNS response used for AS lookups, specifically by returning a DNS response larger than 512 bytes with a crafted compression pointer in the answer NAME field. The vulnerability causes a reliable crash due to improper boundary handling in the dn_expand() function. This issue affects mtr through version 0.96 and was fixed in a specific commit.
AI Analysis
Technical Summary
An out-of-bound read vulnerability exists in the ipinfo_lookup() function of mtr, caused by improper handling of DNS TXT responses larger than 512 bytes with crafted compression pointers. The function uses the response length as the end-of-message boundary for dn_expand(), leading to a reliable crash when parsing malicious DNS responses. This vulnerability affects mtr versions up to 0.96 and was resolved in commit 48e1794414d338ce47abc0f27c25ade8788af9c3.
Potential Impact
Successful exploitation results in a reliable crash of the mtr utility, causing a denial of service. There is no indication of code execution or data disclosure from the provided information.
Mitigation Recommendations
A fix is available and was introduced in commit 48e1794414d338ce47abc0f27c25ade8788af9c3. Users should upgrade mtr to a version that includes this commit or later. Patch status is confirmed by the vendor advisory. No additional mitigation steps are indicated.
UBUNTU-CVE-2026-14461
Description
The mtr utility is affected by an out-of-bound read vulnerability in the ipinfo_lookup() function. This flaw can be triggered by an attacker who controls the TXT DNS response used for AS lookups, specifically by returning a DNS response larger than 512 bytes with a crafted compression pointer in the answer NAME field. The vulnerability causes a reliable crash due to improper boundary handling in the dn_expand() function. This issue affects mtr through version 0.96 and was fixed in a specific commit.
CVSS v4.0
Affected software
pkg:deb/ubuntu/[email protected]?arch=source&distro=xenialpkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
An out-of-bound read vulnerability exists in the ipinfo_lookup() function of mtr, caused by improper handling of DNS TXT responses larger than 512 bytes with crafted compression pointers. The function uses the response length as the end-of-message boundary for dn_expand(), leading to a reliable crash when parsing malicious DNS responses. This vulnerability affects mtr versions up to 0.96 and was resolved in commit 48e1794414d338ce47abc0f27c25ade8788af9c3.
Potential Impact
Successful exploitation results in a reliable crash of the mtr utility, causing a denial of service. There is no indication of code execution or data disclosure from the provided information.
Mitigation Recommendations
A fix is available and was introduced in commit 48e1794414d338ce47abc0f27c25ade8788af9c3. Users should upgrade mtr to a version that includes this commit or later. Patch status is confirmed by the vendor advisory. No additional mitigation steps are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-14461
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:14.04:LTS","Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 4.0
Threat ID: 6a58b4f568715ace43db2017
Added to database: 07/16/2026, 10:39:49 UTC
Last enriched: 07/16/2026, 14:01:18 UTC
Last updated: 07/31/2026, 19:24:46 UTC
Views: 23
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.