Article

    Cyber News / Article / Vulnerability in BitWizard mtr software

    Vulnerability in BitWizard mtr software
    CE
    CERT Polska-2026-07-10

    Vulnerability in BitWizard mtr software

    CERT Polska has received a report about vulnerability in BitWizard mtr software and participated in coordination of its disclosure.

    The vulnerabilityCVE-2026-14461: mtr is vulnerable to Out-of-bound read vulnerability inipinfo_lookup()function. An attacker who can influence the TXT response used for AS lookups can trigger this bug by returning a DNS response that is larger than 512 bytes and uses a crafted compression pointer in the answerNAMEfield.ipinfo_lookup()function uses the length of the response as the end-of-message boundary fordn_expand()function. The result is a reliable crash.

    This issue exists in the mtr through version 0.96 and it was fixed in commit 48e1794414d338ce47abc0f27c25ade8788af9c3.

    We thank Michał Majchrowicz and Marcin Wyczechowski from AFINE Team for the responsible vulnerability report.

    Original source