RHSA-2026:61341: Moderate: NetworkManager security update
NetworkManager is a system network service that manages network devices and connections, attempting to keep active network connectivity when available. Its capabilities include managing Ethernet, wireless, mobile broadband (WWAN), and PPPoE devices, as well as providing VPN integration with a variety of different VPN services.Security Fix(es): NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend (CVE-2026-10805) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Apply the NetworkManager security update that fixes local privilege escalation via malformed MUD URLs in the dhclient backend (CVE-2026-10805).
Event History
Frequently Asked Questions
What level of access would an attacker need?
The issue is described as a local privilege escalation, so exploitation requires local access. It involves malformed MUD URLs handled by NetworkManager's dhclient backend.
Can I determine whether a particular NetworkManager version or configuration is affected from this advisory?
No. The provided information does not list affected or fixed versions, whether the dhclient backend is enabled by default, or a detection method for prior exploitation.
What mitigation is identified if an update cannot be applied immediately?
No temporary mitigation or workaround is provided in the advisory data. The stated remediation is the NetworkManager security update.