Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-19685

Опубликовано: 24 авг. 2026
Источник: debian

Описание

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
network-managerfixed1.58.1-1package
network-managernot-affectedtrixiepackage
network-managernot-affectedbookwormpackage
network-managernot-affectedbullseyepackage

Примечания

  • https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2513

  • Introduced with: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/e85cc46d0b36cdba50fe8411cc93d55a49ebfccf (1.57.1-dev)

  • The introducing commit is part of the patchseries for CVE-2025-9615

  • Fixed by: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/a8e87381a3e70060abd721d9a347f42b2ba68e6e

  • Fixed by: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/15aa1a8963ee014f5eb8306b305b158293c10643 (1.58.1)

Связанные уязвимости

CVSS3: 7.1
ubuntu
27 дней назад

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

CVSS3: 7.1
redhat
27 дней назад

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

CVSS3: 7.1
nvd
27 дней назад

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

CVSS3: 9.8
github
27 дней назад

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

suse-cvrf
14 дней назад

Security update for NetworkManager