PT-2026-69045 · Libvirt+2 · Libvirt+2
CVE-2026-61477
·
Published
2026-08-07
·
Updated
2026-09-03
CVSS v3.1
2.3
Low
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
libvirt (affected versions not specified)
Description
An injection issue exists in the virtual network driver of libvirt. The network XML parser fails to remove newline characters from DNS TXT record value attributes and SRV record domain/target attributes. Because these values are written directly into the generated dnsmasq configuration file, a user with permissions to define virtual networks can inject arbitrary dnsmasq configuration directives, such as
dhcp-script, resulting in arbitrary command execution with root privileges.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Ubuntu
Libvirt