A remotely triggerable out-of-bounds read vulnerability was disclosed in traceroute 2.1.2, affecting MPLS extension parsing when the tool is run with -e. Researcher Mohamed Aziz Rahmouni reported that in traceroute/traceroute.c, the packet buffer pointer is advanced past the IP header after recvmsg(), but the packet length variable is not reduced before handle_extensions() is called. That mismatch can cause the parser to read past the actual received packet boundary and into uninitialized stack memory in buf[1280] when processing a crafted ICMP Time Exceeded response carrying MPLS extensions from an on-path network device.
The researcher said the flaw was identified through manual code review and dynamic fuzzing, confirmed with a working proof of concept, and could be corrected with a one-line fix that subtracts the header length from the packet length after advancing the buffer pointer. traceroute maintainer Dmitry Butskoy acknowledged the report on the oss-sec mailing list and said he would review it within hours, while the disclosure followed a 90-day responsible disclosure timeline with public technical details planned unless a patch is released sooner.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
In follow-up oss-sec discussion, Dmitry Butskoy said the cited code had long included the key "n -= hlen;" logic, including in current traceroute releases, and Solar Designer questioned why the report targeted 2.1.2. The thread indicated the reported MPLS parsing out-of-bounds read was likely based on faulty analysis rather than a confirmed vulnerability.
Dmitry Butskoy replied on oss-sec acknowledging the vulnerability report and said he would review it within a few hours. The follow-up reiterated the planned 90-day disclosure timeline, with public disclosure targeted for 2026-07-27 unless a patch is released sooner.
On the oss-sec mailing list, Mohamed Aziz Rahmouni disclosed an out-of-bounds read vulnerability in traceroute 2.1.2 affecting MPLS extension parsing. The report said the flaw is remotely triggerable by an on-path device via a crafted ICMP Time Exceeded response to traceroute -e, included a confirmed proof of concept, and proposed a one-line fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.