Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5073 articles · 189137 vulns · 37/41 feeds (7d)
← Back to list
2.3
CVE-2026-61477EXPLOITED
red hat · red hat enterprise linux

Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection

Description

An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are written verbatim into the dnsmasq configuration file generated by the network driver, allowing a user with permission to define virtual networks to inject arbitrary dnsmasq configuration directives such as dhcp-script, leading to arbitrary command execution as root.

Affected Products

VendorProductVersions
red hatred hat enterprise linux—

References

  • https://access.redhat.com/security/cve/CVE-2026-61477(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2512066(issue-tracking, x_refsource_REDHAT)
  • https://gitlab.com/libvirt/libvirt/-/commit/3cfc77963b512d809348fca07f97fe924fac9a05

Related News (2 articles)

Tier A
Microsoft MSRC1d ago
CVE-2026-61477 Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-61477 | Red Hat Enterprise Linux Network XML Parser code injection
→ No new info (linked only)
CVSS 3.12.3 LOW
VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-93
PublishedAug 7, 2026
Last enriched5d ago
Tags
remote code executionfile manipulationdenial of servicemultiple vulnerabilities
Trending Score42
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-4480EXPKEV
Samba: samba: remote code execution in printing subsystem via unescaped job description
Trending: 48
NONECVE-2026-73433EXP
Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd parsing leading to out-of-bounds read/write
Trending: 47
NONECVE-2026-59091EXP
Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file
Trending: 46
MEDIUMCVE-2026-6426EXP
Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds access
Trending: 44
NONECVE-2026-59090EXP
Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow
Trending: 43

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 7, 2026
Discovered by ZDM
Aug 7, 2026
Actively Exploited
Aug 7, 2026
Exploit Available
Aug 7, 2026