RHSA-2026:58572: Moderate: NetworkManager security update
NetworkManager is a system network service that manages network devices and connections, attempting to keep active network connectivity when available. Its capabilities include managing Ethernet, wireless, mobile broadband (WWAN), and PPPoE devices, as well as providing VPN integration with a variety of different VPN services.Security Fix(es): NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend (CVE-2026-10805) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The issue is described as a local privilege escalation, so exploitation requires local access to a system running the affected NetworkManager component.
Which NetworkManager component is involved?
The vulnerability is in NetworkManager's dhclient backend and is triggered through malformed MUD URLs.
What is the recommended remediation?
Apply the NetworkManager security update provided by RHSA-2026:58572.