An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are written verbatim into the dnsmasq configuration file generated by the network driver, allowing a user with permission to define virtual networks to inject arbitrary dnsmasq configuration directives such as dhcp-script, leading to arbitrary command execution as root.
{
"cna_assigner": "redhat",
"cwe_ids": [
"CWE-93"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61477.json"
}"2026-08-09T08:05:11Z"
[
{
"target": {
"file": "tests/virschematest.c"
},
"digest": {
"line_hashes": [
"133954233605005987563308552535571751658",
"158925290585703084243811498830184378796",
"331176216352009358854267268860545906823",
"272133549940180185180000244465031439861",
"158217075899345673306074539861010970635",
"89292368838837576724719707065075190737"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-61477-59ff76e3",
"source": "https://gitlab.com/libvirt/libvirt@3cfc77963b512d809348fca07f97fe924fac9a05"
},
{
"target": {
"file": "tests/networkxml2xmlupdatetest.c"
},
"digest": {
"line_hashes": [
"68888094752431916243215473676037035078",
"288995729072857676923105816093189977134",
"263372141755492121532217804851606768818",
"304629448994027061454879807276276277146",
"295053441786637729800426637453647595756",
"314058758696736851029649596565116007783",
"122203876594600569836802440484042322918",
"158248643069887581582267247176081971581",
"129015924251974993683335803118554697877",
"127262528882123559083757959206626687266",
"27014478525874794620092802822762412177",
"209382760214502057303868709128332907654"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-61477-6cfd6e65",
"source": "https://gitlab.com/libvirt/libvirt@3cfc77963b512d809348fca07f97fe924fac9a05"
},
{
"target": {
"file": "tests/networkxmlconftest.c"
},
"digest": {
"line_hashes": [
"231838115855685295673848431184348645800",
"80414928417321096168291858750051984094",
"146654114811108915776984899503214448708",
"102044163281895025833985634876325822756",
"192135900847403292100438467012774094360"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-61477-8fce7865",
"source": "https://gitlab.com/libvirt/libvirt@3cfc77963b512d809348fca07f97fe924fac9a05"
},
{
"target": {
"function": "mymain",
"file": "tests/networkxmlconftest.c"
},
"digest": {
"length": 2925.0,
"function_hash": "66821359014778008981731771224155503636"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2026-61477-9042f4e4",
"source": "https://gitlab.com/libvirt/libvirt@3cfc77963b512d809348fca07f97fe924fac9a05"
},
{
"target": {
"function": "mymain",
"file": "tests/networkxml2xmlupdatetest.c"
},
"digest": {
"length": 7298.0,
"function_hash": "337682357011542162974494907701534235800"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2026-61477-a6fdf3b0",
"source": "https://gitlab.com/libvirt/libvirt@3cfc77963b512d809348fca07f97fe924fac9a05"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61477.json"