[Pkg-utopia-maintainers] Bug#1139285: network-manager: CVE-2026-10805
Salvatore Bonaccorso
carnil at debian.org
Wed Jul 22 23:04:54 BST 2026
Hi Michael,
On Wed, Jul 22, 2026 at 05:37:44PM +0200, Michael Biebl wrote:
> Version: 1.58.0-1
>
> Hi
>
> On Mon, 8 Jun 2026 11:39:25 +0200 =?UTF-8?Q?Moritz_M=C3=BChlenhoff?=
> <jmm at inutil.org> wrote:
> > Source: network-manager
> > X-Debbugs-CC: team at security.debian.org
> > Severity: normal
> > Tags: security
> >
> > Hi,
> >
> > The following vulnerability was published for network-manager.
> >
> > CVE-2026-10805[0]:
> > | A flaw was found in NetworkManager. This local privilege escalation
> > | vulnerability exists in NetworkManager's dhclient backend when
> > | processing malformed Manufacturer Usage Description (MUD) URLs. A
> > | local user can exploit this flaw to escalate privileges by
> > | triggering a script via a crafted MUD URL, provided an administrator
> > | has explicitly configured NetworkManager to use dhclient. This issue
> > | does not affect default configurations of NetworkManager.
> >
> > The only reference here is https://bugzilla.redhat.com/show_bug.cgi?id=2484613
> > but given that NM defaults to the internal DHCP client since ages and
> > forky doesn't even include dhclient anymore, this seems really harmless
> >
> >
> > If you fix the vulnerability please also make sure to include the
> > CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
> >
> > For further information see:
> >
> > [0] https://security-tracker.debian.org/tracker/CVE-2026-10805
> > https://www.cve.org/CVERecord?id=CVE-2026-10805
> >
> > Please adjust the affected versions in the BTS as needed.
> >
> >
>
> This has been fixed in 1.58.0-1
>
> First by https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2426
> (just in case someone wants to backport this to stable)
>
> But later upstream decided to remove dhclient support completely:
> https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2427
>
> So, the vulnerable code is no longer part of 1.58.0-1 (which is currently in
> expedrimental)
Thanks i have updated the security-tracker metadata on it.
Regards,
Salvatore
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 963 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-utopia-maintainers/attachments/20260723/4c4390fd/attachment.sig>
More information about the Pkg-utopia-maintainers
mailing list