Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-9615

Опубликовано: 26 янв. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
network-managerfixed1.54.3-1package
network-managerignoredtrixiepackage
network-managerignoredbookwormpackage
network-managerignoredbullseyepackage

Примечания

  • https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2324

  • https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/issues/1809 (not yet public)

  • https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2327 (nm-1-52 backport)

  • The issue is in network-manager and the CVE associated with it. A patched

  • network-manager daemon will refuse to activating the private connections from plugins

  • without the fix. The VPN plugins need a corresponding update to keep then functional

  • when private connections are configured.

EPSS

Процентиль: 0%
0.00005
Низкий

Связанные уязвимости

CVSS3: 3.3
ubuntu
12 дней назад

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.

CVSS3: 3.3
nvd
12 дней назад

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.

CVSS3: 3.3
github
12 дней назад

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.

EPSS

Процентиль: 0%
0.00005
Низкий