{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2026-72694: refuse a symbolic link at the pid file path, create the\n  file with O_CREAT|O_EXCL and chown the open handle rather than the path.\n  Started as root in daemon mode, mrtg created and chowned the pid file\n  before dropping privileges, so a pre-placed symlink could have root\n  chown an arbitrary file to the daemon user.",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1788267640",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1788267640"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/tuxcare9.6esu/advisories/2026/clsa-2026_1788267640.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-01T13:01:12Z",
      "generator": {
        "date": "2026-09-01T13:01:12Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1788267640",
      "initial_release_date": "2026-09-01T13:01:12Z",
      "revision_history": [
        {
          "date": "2026-09-01T13:01:12Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "mrtg: Fix of CVE-2026-72694"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "AlmaLinux 9.6",
                "product": {
                  "name": "AlmaLinux 9.6",
                  "product_id": "AlmaLinux-9.6",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:almalinux:almalinux:9.6:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "AlmaLinux"
          }
        ],
        "category": "vendor",
        "name": "AlmaLinux OS Foundation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Rocky Linux 9.6",
                "product": {
                  "name": "Rocky Linux 9.6",
                  "product_id": "Rocky Linux-9.6",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:resf:rocky_linux:9.6:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Rocky Linux"
          }
        ],
        "category": "vendor",
        "name": "Rocky Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mrtg-0:2.17.7-11.el9_6.tuxcare.els1.x86_64",
                "product": {
                  "name": "mrtg-0:2.17.7-11.el9_6.tuxcare.els1.x86_64",
                  "product_id": "mrtg-0:2.17.7-11.el9_6.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/mrtg@2.17.7-11.el9_6.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mrtg-0:2.17.7-11.el9_6.tuxcare.els1.x86_64 as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:mrtg-0:2.17.7-11.el9_6.tuxcare.els1.x86_64"
        },
        "product_reference": "mrtg-0:2.17.7-11.el9_6.tuxcare.els1.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mrtg-0:2.17.7-11.el9_6.tuxcare.els1.x86_64 as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:mrtg-0:2.17.7-11.el9_6.tuxcare.els1.x86_64"
        },
        "product_reference": "mrtg-0:2.17.7-11.el9_6.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Rocky Linux-9.6"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-72694",
      "cwe": {
        "id": "CWE-59",
        "name": "Improper Link Resolution Before File Access ('Link Following')"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. This can lead to local privilege escalation, allowing unauthorized access to or modification of sensitive files.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.6:mrtg-0:2.17.7-11.el9_6.tuxcare.els1.x86_64",
          "Rocky Linux-9.6:mrtg-0:2.17.7-11.el9_6.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-72694"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:57596",
          "url": "https://access.redhat.com/errata/RHSA-2026:57596"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:57600",
          "url": "https://access.redhat.com/errata/RHSA-2026:57600"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-72694",
          "url": "https://access.redhat.com/security/cve/CVE-2026-72694"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2460973",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460973"
        }
      ],
      "release_date": "2026-08-11T09:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:00:42.173852Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1788267640",
          "product_ids": [
            "AlmaLinux-9.6:mrtg-0:2.17.7-11.el9_6.tuxcare.els1.x86_64",
            "Rocky Linux-9.6:mrtg-0:2.17.7-11.el9_6.tuxcare.els1.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1788267640"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}