Описание
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.
Отчет
This issue is limited to WPA-Enterprise (802.1X) network connections; open and WPA2-Personal (PSK) networks are not affected. Exploitation requires an unprivileged, active local user session holding the (commonly passwordless on desktop systems) settings.modify.own polkit permission; the flaw is not reachable from a remote or inactive SSH session. NetworkManager is the sole affected component: wpa_supplicant/hostapd are downstream consumers that correctly use whatever ca_path directory they are handed and require no change. This is an incomplete fix for CVE-2025-9615 - the 802-1x.ca-path and phase2-ca-path directory-valued properties were not covered by the private_user guard applied to the sibling FILE-typed certificate/key properties and the pac-file property in that earlier fix.
Меры по смягчению последствий
Upstream fix is public: NetworkManager rejects 802-1x.ca-path and 802-1x.phase2-ca-path on private connections (those with connection.permissions) and requires ca-cert or system-ca-certs instead. Fixed upstream in commit a8e87381 (MR 2513), shipped in NetworkManager 1.58.1 and later 1.60 development snapshots. Until the fixed package is installed, use system-wide 802.1X profiles rather than per-user private ones, or set 802-1x.system-ca-certs=yes so the compiled system CA path overrides any user-supplied ca-path.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | NetworkManager | Affected | ||
| Red Hat Enterprise Linux 6 | NetworkManager | Not affected | ||
| Red Hat Enterprise Linux 7 | NetworkManager | Not affected | ||
| Red Hat Enterprise Linux 8 | NetworkManager | Not affected | ||
| Red Hat Enterprise Linux 9 | NetworkManager | Not affected | ||
| Red Hat Hardened Images | NetworkManager | Not affected | ||
| Red Hat OpenShift Container Platform 4 | NetworkManager | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
(NetworkManager did not apply the private_user restriction to the 802-1 ...)
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.
NetworkManager did not apply the private_user restriction to the 802-1 ...
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.
EPSS
7.1 High
CVSS3