Bug 2533685

Summary: CVE-2026-91837 NetworkManager-iodine: NetworkManager-iodine: local privilege escalation to root via nameserver option injection [fedora-all]
Product: [Fedora] Fedora Reporter: Vladimir Vasilev <vvasilev>
Component: NetworkManager-iodineAssignee: Dan Fruehauf <malkodan>
Status: MODIFIED --- QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: high    
Version: rawhideCC: malkodan
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["35094934-bb4e-4ed8-ae3c-1bfb72c3a1a6"]}
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2533634    

Description Vladimir Vasilev 2026-09-15 10:54:37 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A privilege escalation flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. When establishing an iodine VPN connection, nm-iodine-service passes the user-controlled "nameserver" setting from the connection profile to the iodine client binary on the command line without an option terminator. A nameserver value prefixed with "-d" can be reinterpreted by iodine's argument parser as the TUN device name option. Iodine truncates this device name to 15 bytes when calling the kernel's TUNSETIFF ioctl, but keeps the full (up to 250-byte) string in a global buffer that is later interpolated, unsanitized, into an ifconfig command executed via system(). Because this command runs before iodine drops privileges via chroot(), setgid(), and setuid(), a local unprivileged user can embed shell metacharacters in the nameserver value of a VPN connection profile to execute arbitrary commands as root.

Comment 1 Dan Fruehauf 2026-09-20 06:21:04 UTC
Liaised with Guido Gunther, who formulated a patch for it:
https://gitlab.gnome.org/GNOME/network-manager-iodine/-/merge_requests/6

Rawhide build:
https://koji.fedoraproject.org/koji/taskinfo?taskID=150426260

Will be pushed to f43, f44 and f45.

Comment 2 Fedora Update System 2026-09-20 06:43:07 UTC
FEDORA-2026-ccf41b012c (NetworkManager-iodine-1.2.0-29.fc45) has been submitted as an update to Fedora 45.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-ccf41b012c

Comment 3 Fedora Update System 2026-09-20 07:09:27 UTC
FEDORA-2026-5463db437e (NetworkManager-iodine-1.2.0-29.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-5463db437e

Comment 4 Fedora Update System 2026-09-20 07:39:59 UTC
FEDORA-2026-d3a0471c75 (NetworkManager-iodine-1.2.0-29.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-d3a0471c75