Bug 2376353 (CVE-2025-49809) - CVE-2025-49809 mtr: From CVEorg collector
Summary: CVE-2025-49809 mtr: From CVEorg collector
Keywords:
Status: NEW
Alias: CVE-2025-49809
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2376430 2376431
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-07-04 13:01 UTC by OSIDB Bzimport
Modified: 2025-07-16 13:45 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-07-04 13:01:13 UTC
mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment variable. NOTE: mtr on macOS may often have Sudo rules, as an indirect consequence of Homebrew not installing setuid binaries.

Comment 2 Michal Sekletar 2025-07-16 13:45:28 UTC
Note that we have closed all RHEL trackers for this as NOTABUG because RHEL versions of mtr are not affected to begin with and proposed fix doesn't apply to mtr in RHEL context (i.e. no custom mtr sudo rules are needed).


Note You need to log in before you can comment on or make changes to this bug.