[Pkg-utopia-maintainers] Bug#1139285: network-manager: CVE-2026-10805

Salvatore Bonaccorso carnil at debian.org
Wed Jul 22 23:04:54 BST 2026


Hi Michael,

On Wed, Jul 22, 2026 at 05:37:44PM +0200, Michael Biebl wrote:
> Version: 1.58.0-1
> 
> Hi
> 
> On Mon, 8 Jun 2026 11:39:25 +0200 =?UTF-8?Q?Moritz_M=C3=BChlenhoff?=
> <jmm at inutil.org> wrote:
> > Source: network-manager
> > X-Debbugs-CC: team at security.debian.org
> > Severity: normal
> > Tags: security
> > 
> > Hi,
> > 
> > The following vulnerability was published for network-manager.
> > 
> > CVE-2026-10805[0]:
> > | A flaw was found in NetworkManager. This local privilege escalation
> > | vulnerability exists in NetworkManager's dhclient backend when
> > | processing malformed Manufacturer Usage Description (MUD) URLs. A
> > | local user can exploit this flaw to escalate privileges by
> > | triggering a script via a crafted MUD URL, provided an administrator
> > | has explicitly configured NetworkManager to use dhclient. This issue
> > | does not affect default configurations of NetworkManager.
> > 
> > The only reference here is https://bugzilla.redhat.com/show_bug.cgi?id=2484613
> > but given that NM defaults to the internal DHCP client since ages and
> > forky doesn't even include dhclient anymore, this seems really harmless	
> > 
> > 
> > If you fix the vulnerability please also make sure to include the
> > CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
> > 
> > For further information see:
> > 
> > [0] https://security-tracker.debian.org/tracker/CVE-2026-10805
> >     https://www.cve.org/CVERecord?id=CVE-2026-10805
> > 
> > Please adjust the affected versions in the BTS as needed.
> > 
> > 
> 
> This has been fixed in 1.58.0-1
> 
> First by https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2426
> (just in case someone wants to backport this to stable)
> 
> But later upstream decided to remove dhclient support completely:
> https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2427
> 
> So, the vulnerable code is no longer part of 1.58.0-1 (which is currently in
> expedrimental)

Thanks i have updated the security-tracker metadata on it.

Regards,
Salvatore
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 963 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-utopia-maintainers/attachments/20260723/4c4390fd/attachment.sig>


More information about the Pkg-utopia-maintainers mailing list