Bug 2484613 (CVE-2026-10805) - CVE-2026-10805 NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend
Summary: CVE-2026-10805 NetworkManager: NetworkManager: Local privilege escalation via...
Keywords:
Status: NEW
Alias: CVE-2026-10805
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-04 05:12 UTC by OSIDB Bzimport
Modified: 2026-08-31 14:23 UTC (History)
32 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:58555 0 None None None 2026-08-24 05:21:04 UTC
Red Hat Product Errata RHSA-2026:58572 0 None None None 2026-08-24 06:39:19 UTC
Red Hat Product Errata RHSA-2026:61239 0 None None None 2026-08-31 03:15:11 UTC
Red Hat Product Errata RHSA-2026:61243 0 None None None 2026-08-31 05:54:38 UTC
Red Hat Product Errata RHSA-2026:61244 0 None None None 2026-08-31 04:50:57 UTC
Red Hat Product Errata RHSA-2026:61341 0 None None None 2026-08-31 14:23:05 UTC
Red Hat Product Errata RHSA-2026:61572 0 None None None 2026-08-31 14:22:00 UTC
Red Hat Product Errata RHSA-2026:61580 0 None None None 2026-08-31 14:07:04 UTC

Description OSIDB Bzimport 2026-06-04 05:12:04 UTC
A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.

Comment 3 errata-xmlrpc 2026-08-24 05:21:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:58555 https://access.redhat.com/errata/RHSA-2026:58555

Comment 4 errata-xmlrpc 2026-08-24 06:39:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:58572 https://access.redhat.com/errata/RHSA-2026:58572

Comment 6 errata-xmlrpc 2026-08-31 03:15:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:61239 https://access.redhat.com/errata/RHSA-2026:61239

Comment 7 errata-xmlrpc 2026-08-31 04:50:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:61244 https://access.redhat.com/errata/RHSA-2026:61244

Comment 8 errata-xmlrpc 2026-08-31 05:54:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:61243 https://access.redhat.com/errata/RHSA-2026:61243

Comment 9 errata-xmlrpc 2026-08-31 14:07:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:61580 https://access.redhat.com/errata/RHSA-2026:61580

Comment 10 errata-xmlrpc 2026-08-31 14:21:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:61572 https://access.redhat.com/errata/RHSA-2026:61572

Comment 11 errata-xmlrpc 2026-08-31 14:23:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:61341 https://access.redhat.com/errata/RHSA-2026:61341


Note You need to log in before you can comment on or make changes to this bug.