RHSA-2026:57596: Important: mrtg security update
Important: mrtg security update
Other sources
The Multi Router Traffic Grapher (MRTG) monitors the traffic load on network connections. MRTG generates HTML pages containing PNG images which provide a live visual representation of this traffic.Security Fix(es): mrtg: MRTG daemon symlink-following chown allows local privilege escalation via PID file path manipulation (CVE-2026-72694) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/mrtgto a version that resolves this vulnerability.Fixed in 2.17.10-12.el10_2.1 - Upgrade
Upgrade
redhat/mrtg-debuginfoto a version that resolves this vulnerability.Fixed in 2.17.10-12.el10_2.1 - Upgrade
Upgrade
redhat/mrtg-debugsourceto a version that resolves this vulnerability.Fixed in 2.17.10-12.el10_2.1 - Upgrade
Upgrade
redhat/mrtg-selinuxto a version that resolves this vulnerability.Fixed in 2.17.10-12.el10_2.1 - Upgrade
Upgrade
redhat/mrtgto a version that resolves this vulnerability.Fixed in 2.17.10-12.el10_2.1.aa - Upgrade
Upgrade
redhat/mrtg-debuginfoto a version that resolves this vulnerability.Fixed in 2.17.10-12.el10_2.1.aa - Upgrade
Upgrade
redhat/mrtg-debugsourceto a version that resolves this vulnerability.Fixed in 2.17.10-12.el10_2.1.aa
Event History
Frequently Asked Questions
Which systems are covered by this advisory?
The advisory applies to mrtg on the listed Red Hat Enterprise Linux offerings for x86_64, ARM 64, IBM z Systems, and Power little endian, including the specified Extended Update Support, Extended Life Cycle, four-year support, and four-year updates variants.
What severity is assigned to this update?
This is rated Important with a high severity score of 7 and a listed risk value of 33.