Red HatCVE-2026-61477
Red Hat libvirt: user could define virtual networks to inject arbitrary
Low2.3CVE-2026-61477 · Published Aug 7, 2026 · updated Aug 14, 2026
An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are written verbatim into the dnsmasq configuration file generated by the network driver, allowing a user with permission to define virtual networks to inject arbitrary dnsmasq configuration directives such as dhcp-script, leading to arbitrary command execution as root.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 6 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
| Red Hat Enterprise Linux for NVIDIA 26 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-93
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 7 | Red Hat dracut: command injection | High7.5 | No fix yet |
| Aug 7 | Red Hat p11-kit. A local attacker: integer overflow | Medium6.2 | No fix yet |
| Aug 7 | Red Hat fixfiles script: race condition | Medium4.4 | No fix yet |
| Aug 6 | Red Hat udisks2: privilege escalation | High7.8 | Red Hat+1 more |
| Aug 6 | Red Hat GStreamer gst-plugins-good: denial of service | High7.5 | No fix yet |
| Aug 6 | Red Hat SAML broker: capture-replay | Medium6.4 | No fix yet |