PT-2026-95012 · Mport · Mport

·

CVE-2026-54579

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

2.3

Low

VectorAV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions mport versions prior to 2.7.8
Description The ping() function in libmport/ping.c fails to validate icmp id or icmp seq when accepting ICMP replies and uses a fixed IP-header offset instead of ip hl for parsing. A network attacker capable of injecting or spoofing ICMP replies can influence the selection of mirror latency. Additionally, a malformed packet containing IP options can shift the ICMP header, leading to an out-of-bounds read, which occurs when a program reads data outside the intended boundary of a buffer.
Recommendations Update to version 2.7.8.

Exploit

Fix

Insufficient Verification of Data Authenticity

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54579
GHSA-QC2F-2J7J-M3R7

Affected Products

Mport