Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19685

Опубликовано: 24 авг. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

Отчет

This issue is limited to WPA-Enterprise (802.1X) network connections; open and WPA2-Personal (PSK) networks are not affected. Exploitation requires an unprivileged, active local user session holding the (commonly passwordless on desktop systems) settings.modify.own polkit permission; the flaw is not reachable from a remote or inactive SSH session. NetworkManager is the sole affected component: wpa_supplicant/hostapd are downstream consumers that correctly use whatever ca_path directory they are handed and require no change. This is an incomplete fix for CVE-2025-9615 - the 802-1x.ca-path and phase2-ca-path directory-valued properties were not covered by the private_user guard applied to the sibling FILE-typed certificate/key properties and the pac-file property in that earlier fix.

Меры по смягчению последствий

Upstream fix is public: NetworkManager rejects 802-1x.ca-path and 802-1x.phase2-ca-path on private connections (those with connection.permissions) and requires ca-cert or system-ca-certs instead. Fixed upstream in commit a8e87381 (MR 2513), shipped in NetworkManager 1.58.1 and later 1.60 development snapshots. Until the fixed package is installed, use system-wide 802.1X profiles rather than per-user private ones, or set 802-1x.system-ca-certs=yes so the compiled system CA path overrides any user-supplied ca-path.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10NetworkManagerAffected
Red Hat Enterprise Linux 6NetworkManagerNot affected
Red Hat Enterprise Linux 7NetworkManagerNot affected
Red Hat Enterprise Linux 8NetworkManagerNot affected
Red Hat Enterprise Linux 9NetworkManagerNot affected
Red Hat Hardened ImagesNetworkManagerNot affected
Red Hat OpenShift Container Platform 4NetworkManagerNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2515042NetworkManager: NetworkManager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing WPA-Enterprise server validation bypass (incomplete fix for CVE-2025-9615)

EPSS

Процентиль: 3%
0.00136
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
25 дней назад

(NetworkManager did not apply the private_user restriction to the 802-1 ...)

CVSS3: 7.1
nvd
27 дней назад

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

CVSS3: 7.1
debian
27 дней назад

NetworkManager did not apply the private_user restriction to the 802-1 ...

CVSS3: 9.8
github
27 дней назад

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

EPSS

Процентиль: 3%
0.00136
Низкий

7.1 High

CVSS3