RHSA-2026:61239: Moderate: NetworkManager security update
Moderate: NetworkManager security update
Other sources
NetworkManager is a system network service that manages network devices and connections, attempting to keep active network connectivity when available. Its capabilities include managing Ethernet, wireless, mobile broadband (WWAN), and PPPoE devices, as well as providing VPN integration with a variety of different VPN services.Security Fix(es): NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend (CVE-2026-10805) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
Who could exploit this issue?
An attacker would need local access or the ability to cause NetworkManager's dhclient backend to process a malformed MUD URL. The issue is described as a local privilege escalation.
Which systems are covered by this advisory?
The advisory applies to Red Hat Enterprise Linux for x86_64 Extended Life Cycle Long Life and Red Hat Enterprise Linux Server AUS.
Which NetworkManager component is involved?
The affected code path is NetworkManager's dhclient backend, specifically its handling of malformed MUD URLs.