libvirt是libvirt组织开源的一个虚拟化平台管理工具。 libvirt存在输入验证错误漏洞,该漏洞源于网络XML解析器未从DNS TXT记录值属性和SRV记录域名/目标属性中去除换行符,导致这些值被原样写入dnsmasq配置文件,可能允许具有定义虚拟网络权限的用户注入任意dnsmasq配置指令,从而导致以root身份执行任意命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
| Red Hat | Red Hat Enterprise Linux for NVIDIA 26 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux for NVIDIA 26 | - |
cpe:/a:redhat:enterprise_linux_nvidia:
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15816 | 7.5 HIGH | Dracut: dracut: root code execution via unescaped error message written to sourced emergen |
| CVE-2026-18938 | 6.2 MEDIUM | P11-kit: integer overflow in rpc attribute-array length calculation can under-allocate nes |
| CVE-2026-19079 | 4.4 MEDIUM | Policycoreutils: policycoreutils: toctou race condition in fixfiles allows arbitrary selin |
No comments yet