Injection Vulnerability in libvirt's Virtual Network Driver
CVE-2026-61477

2.3LOW

What is CVE-2026-61477?

An injection vulnerability was identified in the libvirt virtual network driver's XML parser, which fails to adequately sanitize newline characters from DNS TXT record value attributes and SRV record domain or target attributes. This oversight allows users with permissions to define virtual networks to exploit this vulnerability by injecting arbitrary dnsmasq configuration directives into the generated configuration file. Such injections can lead to arbitrary command execution with root privileges, compromising the entire system running the affected libvirt versions.

References

CVSS V3.1

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.