NIXPKGS-2026-2767
GitHub issue
published 17 hours ago
Networkmanager-iodine: networkmanager-iodine: local privilege escalation to root via nameserver option injection
Permalink
CVE-2026-91837
7.8 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
Networkmanager-iodine: networkmanager-iodine: local privilege escalation to root via nameserver option injection
A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting is processed when establishing an iodine VPN connection. By embedding shell metacharacters (special characters that can execute commands) in the 'nameserver' value, an attacker can inject and execute arbitrary commands. These commands run with root privileges before the application drops its elevated permissions, leading to local privilege escalation.
References
Affected products
network-manager-iodine
- *
Matching in nixpkgs
pkgs.networkmanager-iodine
NetworkManager's iodine plugin
-
nixos-unstable -
- nixos-unstable-small 1.2.0-unstable-2026-03-14
-
nixos-26.05 -
- nixos-26.05-small 1.2.0-unstable-2026-03-14
Package maintainers
-
@jtojnar Jan Tojnar <jtojnar@gmail.com>
-
@obadz obadz <obadz-nixos@obadz.com>
-
@Hythera Hythera