On Fri, Jul 10, 2026 at 07:07:01AM -0400, Michael Bommarito wrote:
Add negative tests that feed XML numeric character references for LF ( ) and CR ( ) into the DNS TXT value and SRV domain/target attributes, covering both the network XML parse path and the update API. Literal newlines are insufficient because XML parsers normalize raw attribute whitespace to spaces; the numeric references are what survive to the configuration emitter.
CVE-2026-61477
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com> --- .../dns-txt-record-newline.xml | 1 + .../srv-record-target-newline.xml | 1 + tests/networkxml2xmlupdatetest.c | 12 ++++++++++++ .../nat-network-dns-srv-record-domain-newline.xml | 14 ++++++++++++++ .../nat-network-dns-srv-record-target-newline.xml | 14 ++++++++++++++ .../nat-network-dns-txt-record-newline.xml | 14 ++++++++++++++ tests/networkxmlconftest.c | 3 +++ 7 files changed, 59 insertions(+) create mode 100644 tests/networkxml2xmlupdatein/dns-txt-record-newline.xml create mode 100644 tests/networkxml2xmlupdatein/srv-record-target-newline.xml create mode 100644 tests/networkxmlconfdata/nat-network-dns-srv-record-domain-newline.xml create mode 100644 tests/networkxmlconfdata/nat-network-dns-srv-record-target-newline.xml create mode 100644 tests/networkxmlconfdata/nat-network-dns-txt-record-newline.xml
This tripped up the RNG schema validation, since we have intentionally malformed XML documents. I'm adding: diff --git a/tests/virschematest.c b/tests/virschematest.c index 4faac8d976..42b1a62715 100644 --- a/tests/virschematest.c +++ b/tests/virschematest.c @@ -301,9 +301,17 @@ static const struct testSchemaEntry schemaInterface[] = { { .dir = "tests/interfaceschemadata" }, }; +/* skip tests with completely broken XML */ +static const char *skip_networkxmlconfdata[] = { + "nat-network-dns-srv-record-domain-newline.xml", + "nat-network-dns-srv-record-target-newline.xml", + "nat-network-dns-txt-recor-record-newline.xml", +}; + static const struct testSchemaEntry schemaNetwork[] = { { .dir = "src/network" }, - { .dir = "tests/networkxmlconfdata" }, + { .dir = "tests/networkxmlconfdata", + .skip = skip_networkxmlconfdata }, { .dir = "examples/xml/test/", .dirRegex = "testnet.*" }, { .dir = "tests/networkxml2xmlupdateout" }, With regards, Daniel -- |: https://berrange.com ~~ https://hachyderm.io/@berrange :| |: https://libvirt.org ~~ https://entangle-photo.org :| |: https://pixelfed.art/berrange ~~ https://fstop138.berrange.com :|