What is CVE-2026-61477?
CVE-2026-61477 is an injection vulnerability in libvirt's virtual network driver, where the network XML parser fails to strip newline characters from DNS TXT and SRV record attributes. This leads to verbatim injection into the generated dnsmasq configuration file, potentially compromising network isolation. Users should review VM network configurations and apply the libvirt update.
Azərbaycanca: libvirt virtual şəbəkə sürücüsündə tapılan CVE-2026-61477 injection zəifliyidir. DNS TXT və SRV qeydləri üçün şəbəkə XML parser-i yeni sətir simvollarını silmir ki, bu da dnsmasq konfiqurasiya faylına müdaxiləyə yol aça bilər. Təsirə məruz qalan istifadəçilər virtual maşın şəbəkə konfiqurasiyalarını yoxlamalı və libvirt yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-20
FAQ1
What function of libvirt is affected by CVE-2026-61477?
This vulnerability affects libvirt's virtual network driver, specifically the network XML parser which fails to strip newline characters from DNS TXT and SRV record attributes, leading to injection into the dnsmasq configuration file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.