On Fri, Jul 10, 2026 at 07:06:57AM -0400, Michael Bommarito wrote:
> The network XML schema supports typed DNS records using <dns><txt>
> and <dns><srv> tags, and the TXT and SRV domain/target values
> do not strip XML numeric char refs like &#10; (LF).  As a result,
> these XML values can be used to insert additional configuration
> or commands into the dnsmasq config created by the network driver,
> e.g., a malicious dhcp-script=... line.
> 
> libvirt socket access is already documented as root-equivalent,
> and raw <dnsmasq:options> namespace already exists, so this fix
> should be treated as hardening-only for default deployments that
> do not provide unpriv users with access to configure/extend
> these values.
> 
> The series validates on both the parser and the emitter side:
> 
>   1-2. reject LF/CR in the TXT value and SRV domain/target at XML
>        parse time;
>   3.   add a defensive check in the dnsmasq config emitter so a future
>        parser gap cannot reintroduce directive injection; the raw
>        <dnsmasq:options> namespace is intentionally left untouched;
>   4.   add parse-path and update-API negative tests using &#10;/&#13;.
> 
> Coordinated and assigned CVE-2026-61477 by RH team.
> 
> Testing: built against current master with the network driver and
> tests enabled. The new negative tests fail on unpatched master (the
> expected parse error does not occur) and pass with the series applied,
> across both the network XML parse path and the update API.

Reviewed-by: Daniel P. Berrangé <[email protected]>

and will push shortly. Thank you for providing patches along with your
disclosure.

With regards,
Daniel
-- 
|: https://berrange.com       ~~        https://hachyderm.io/@berrange :|
|: https://libvirt.org          ~~          https://entangle-photo.org :|
|: https://pixelfed.art/berrange   ~~    https://fstop138.berrange.com :|

Reply via email to