Skip to main content

Threats Tagged 'cve-2026-61477'

View all threats tagged with 'cve-2026-61477'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-61477

Threats Tagged 'cve-2026-61477'

Click on any threat for detailed analysis and mitigation recommendations

0

This update for libvirt fixes the following issues: - CVE-2026-18917: integer overflow in `NodeGetFreePages` RPC handler leads to heap buffer overflow and allows for possible local privilege escalation (bsc#1275863). - CVE-2026-61477: newline injection in network XML DNS TXT/SRV fields allows for `dnsmasq` configuration directive injection and can lead to arbitrary code execution as root (bsc#1274576). - CVE-2026-63622: symlink-following in `virFileChownFiles()` allows `swtpm` user to trick the root-level `libvirt` daemon into changing the ownership of an arbitrary file and can lead to privilege escalation (bsc#1275264). - CVE-2026-63623: newly created volume images are temporarily world-readable during clone/convert operations, which can lead to sensitive information disclosure (bsc#1275265). - CVE-2026-77159: root `chown()` on `swtpm` logfile follows symlinks and allows for root-owned file ownership changes, which can lead to privilege escalation (bsc#1274946).

Join the discussion

An injection vulnerability exists in libvirt's virtual network driver due to improper handling of newline characters in DNS TXT and SRV record attributes. This flaw allows users with permission to define virtual networks to inject arbitrary dnsmasq configuration directives, potentially leading to arbitrary command execution as root. The vulnerability has a medium severity rating with a CVSS score of 2.3. A patch is available to address this issue.

Join the discussion

An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are written verbatim into the dnsmasq configuration file generated by the network driver, allowing a user with permission to define virtual networks to inject arbitrary dnsmasq configuration directives such as dhcp-script, leading to arbitrary command execution as root.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: cve-2026-61477
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses