| Name | CVE-2026-61477 |
| Description | An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are written verbatim into the dnsmasq configuration file generated by the network driver, allowing a user with permission to define virtual networks to inject arbitrary dnsmasq configuration directives such as dhcp-script, leading to arbitrary command execution as root. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| libvirt (PTS) | bullseye | 7.0.0-3+deb11u3 | vulnerable |
| bullseye (security) | 7.0.0-3+deb11u4 | vulnerable | |
| bookworm | 9.0.0-4+deb12u2 | vulnerable | |
| trixie | 11.3.0-3+deb13u2 | vulnerable | |
| forky, sid | 12.6.0-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| libvirt | source | (unstable) | 12.6.0-1 |
[trixie] - libvirt <no-dsa> (Minor issue)
Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/d44836a1dc6771ac22f69755fc69bf730f0eec87 (v12.6.0-rc1)
Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/289ffa796d737a79a4c05d07232ebd75def9a12a (v12.6.0-rc1)
Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/cb8974b923e3c40cde96f0c7bceaa638f7f9c72b (v12.6.0-rc1)
Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/3cfc77963b512d809348fca07f97fe924fac9a05 (v12.6.0-rc1)