Networkmanager-iodine: networkmanager-iodine: local privilege escalation to root via nameserver option injection
Summary
| CVE | CVE-2026-91837 |
|---|---|
| State | PUBLISHED |
| Assigner | fedora |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-25 17:17:18 UTC |
| Updated | 2026-09-30 19:57:08 UTC |
| Description | A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting is processed when establishing an iodine VPN connection. By embedding shell metacharacters (special characters that can execute commands) in the 'nameserver' value, an attacker can inject and execute arbitrary commands. These commands run with root privileges before the application drops its elevated permissions, leading to local privilege escalation. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.001360000 probability, percentile 0.025440000 (date 2026-10-06)
Problem Types: CWE-78 | CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | GNOME | NetworkManager-iodine | affected * semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/security/cve/CVE-2026-91837 | [email protected] | access.redhat.com | |
| bugzilla.redhat.com/show_bug.cgi | [email protected] | bugzilla.redhat.com | |
| gitlab.gnome.org/GNOME/network-manager-iodine/-/work_items/4 | [email protected] | gitlab.gnome.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Red Hat would like to thank Andreas Gabriel Berbescu for reporting this issue. (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-09-15T09:27:50.959Z | Reported to Red Hat. |
| CNA | 2026-09-15T09:25:02.015Z | Made public. |
Workarounds
CNA: To mitigate this issue, remove the `NetworkManager-iodine` and `iodine` packages if they are not required for system functionality. These packages are not installed by default in minimal Red Hat Enterprise Linux installations. ```bash sudo dnf remove NetworkManager-iodine iodine ``` If these packages are necessary, ensure that only trusted users have the ability to create and activate VPN connections.