RHSA-2026:61244: Moderate: NetworkManager security update
NetworkManager is a system network service that manages network devices and connections, attempting to keep active network connectivity when available. Its capabilities include managing Ethernet, wireless, mobile broadband (WWAN), and PPPoE devices, as well as providing VPN integration with a variety of different VPN services.Security Fix(es): NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend (CVE-2026-10805) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NetworkManagerto a version that resolves this vulnerability.Patch CVE-2026-10805
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue is described as a local privilege escalation, so exploitation requires local access. The attacker would use malformed MUD URLs involving NetworkManager's dhclient backend.
Which NetworkManager deployments are relevant?
The affected code path is NetworkManager's dhclient backend. The advisory does not state whether other DHCP backends, configurations, or default installations are affected.