The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement messages; the option body is passed to resolvconf(8) unmodified.
resolvconf(8) is a shell script which does not validate its input. A lack of quoting meant that shell commands pass as input to resolvconf(8) may be executed.
References
Configurations
No configuration.
History
09 Mar 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
09 Mar 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-09 12:16
Updated : 2026-03-09 14:16
NVD link : CVE-2025-14558
Mitre link : CVE-2025-14558
CVE.ORG link : CVE-2025-14558
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation
