An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are written verbatim into the dnsmasq configuration file generated by the network driver, allowing a user with permission to define virtual networks to inject arbitrary dnsmasq configuration directives such as dhcp-script, leading to arbitrary command execution as root.
Metrics
Affected Vendors & Products
References
History
Sat, 08 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libvirt
Libvirt libvirt Redhat enterprise Linux For Nvidia 26 |
|
| Vendors & Products |
Libvirt
Libvirt libvirt Redhat enterprise Linux For Nvidia 26 |
Sat, 08 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 07 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are written verbatim into the dnsmasq configuration file generated by the network driver, allowing a user with permission to define virtual networks to inject arbitrary dnsmasq configuration directives such as dhcp-script, leading to arbitrary command execution as root. | |
| Title | Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat enterprise Linux Nvidia |
|
| Weaknesses | CWE-93 | |
| CPEs | cpe:/a:redhat:enterprise_linux_nvidia: cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat enterprise Linux Nvidia |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-07T18:21:52.947Z
Reserved: 2026-07-09T16:18:42.859Z
Link: CVE-2026-61477
Updated: 2026-08-07T18:21:48.858Z
No data.
OpenCVE Enrichment
Updated: 2026-08-08T20:53:09Z