Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-9615

Опубликовано: 12 дек. 2025
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.

Меры по смягчению последствий

SELinux is shipped out of the box in targeted enforcing mode, which prevents processes from having unwanted permissions and mitigates this attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6NetworkManagerOut of support scope
Red Hat Enterprise Linux 7NetworkManagerFix deferred
Red Hat Enterprise Linux 8NetworkManagerFix deferred
Red Hat OpenShift Container Platform 4NetworkManagerAffected
Red Hat Enterprise Linux 10NetworkManagerFixedRHSA-2026:1814219.05.2026
Red Hat Enterprise Linux 9NetworkManagerFixedRHSA-2026:1859719.05.2026
Red Hat Enterprise Linux 9NetworkManagerFixedRHSA-2026:1859719.05.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-281
https://bugzilla.redhat.com/show_bug.cgi?id=2391503NetworkManager: NetworkManager File Access

EPSS

Процентиль: 6%
0.00162
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
6 месяцев назад

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.

CVSS3: 3.3
nvd
6 месяцев назад

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.

CVSS3: 3.3
debian
6 месяцев назад

A flaw was found in NetworkManager. The NetworkManager package allows ...

suse-cvrf
около 2 месяцев назад

Security update for NetworkManager

suse-cvrf
4 месяца назад

Security update for NetworkManager

EPSS

Процентиль: 6%
0.00162
Низкий

3.3 Low

CVSS3