Bug#1144393: mrtg: CVE-2026-72694

Moritz Mühlenhoff <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <an8ubtG4Im-TsG9j__7169.31552612863$1786719937$gmane$org@pisco.westfalen.local>
Source: mrtg
X-Debbugs-CC: [email protected]
Severity: grave
Tags: security

Hi,

The following vulnerability was published for mrtg.

CVE-2026-72694[0]:
| A flaw was found in MRTG. When the MRTG daemon is started as a root
| user and subsequently drops privileges, a local, low-privileged
| attacker can exploit a symbolic link (symlink) following
| vulnerability. By influencing or pre-placing a symlink in the
| process ID (PID) file path, the attacker can trick the root process
| into changing the ownership of an arbitrary existing file to the
| daemon user. This can lead to local privilege escalation, allowing
| unauthorized access to or modification of sensitive files.

https://bugzilla.redhat.com/show_bug.cgi?id=2460973
Fixed by: https://github.com/oetiker/mrtg/commit/30e19216bfadc0148f347cb0a42fd5e2016e6269


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-72694
    https://www.cve.org/CVERecord?id=CVE-2026-72694

Please adjust the affected versions in the BTS as needed.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.