Your message dated Wed, 22 Jul 2026 17:37:44 +0200
with message-id <[email protected]>
and subject line Re: network-manager: CVE-2026-10805
has caused the Debian Bug report #1139285,
regarding network-manager: CVE-2026-10805
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1139285: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139285
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: network-manager
X-Debbugs-CC: [email protected]
Severity: normal
Tags: security
Hi,
The following vulnerability was published for network-manager.
CVE-2026-10805[0]:
| A flaw was found in NetworkManager. This local privilege escalation
| vulnerability exists in NetworkManager's dhclient backend when
| processing malformed Manufacturer Usage Description (MUD) URLs. A
| local user can exploit this flaw to escalate privileges by
| triggering a script via a crafted MUD URL, provided an administrator
| has explicitly configured NetworkManager to use dhclient. This issue
| does not affect default configurations of NetworkManager.
The only reference here is https://bugzilla.redhat.com/show_bug.cgi?id=2484613
but given that NM defaults to the internal DHCP client since ages and
forky doesn't even include dhclient anymore, this seems really harmless
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-10805
https://www.cve.org/CVERecord?id=CVE-2026-10805
Please adjust the affected versions in the BTS as needed.
--- End Message ---
--- Begin Message ---
Version: 1.58.0-1
Hi
On Mon, 8 Jun 2026 11:39:25 +0200 =?UTF-8?Q?Moritz_M=C3=BChlenhoff?=
<[email protected]> wrote:
Source: network-manager
X-Debbugs-CC: [email protected]
Severity: normal
Tags: security
Hi,
The following vulnerability was published for network-manager.
CVE-2026-10805[0]:
| A flaw was found in NetworkManager. This local privilege escalation
| vulnerability exists in NetworkManager's dhclient backend when
| processing malformed Manufacturer Usage Description (MUD) URLs. A
| local user can exploit this flaw to escalate privileges by
| triggering a script via a crafted MUD URL, provided an administrator
| has explicitly configured NetworkManager to use dhclient. This issue
| does not affect default configurations of NetworkManager.
The only reference here is https://bugzilla.redhat.com/show_bug.cgi?id=2484613
but given that NM defaults to the internal DHCP client since ages and
forky doesn't even include dhclient anymore, this seems really harmless
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-10805
https://www.cve.org/CVERecord?id=CVE-2026-10805
Please adjust the affected versions in the BTS as needed.
This has been fixed in 1.58.0-1
First by
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2426
(just in case someone wants to backport this to stable)
But later upstream decided to remove dhclient support completely:
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2427
So, the vulnerable code is no longer part of 1.58.0-1 (which is
currently in expedrimental)
Michael
OpenPGP_signature.asc
Description: OpenPGP digital signature
--- End Message ---