Описание
Security update for NetworkManager
This update for NetworkManager fixes the following issues:
- CVE-2026-10805: Local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696).
- CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764).
Список пакетов
Container suse/hpc/warewulf4-x86_64/sle-hpc-node:latest
Image SLES15-SP6-SAP
Image SLES15-SP6-SAP-Azure
Image SLES15-SP6-SAPCAL
Image SLES15-SP6-SAPCAL-Azure
SUSE Linux Enterprise Module for Basesystem 15 SP7
SUSE Linux Enterprise Module for Desktop Applications 15 SP7
SUSE Linux Enterprise Server 15 SP6-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP6
SUSE Linux Enterprise Workstation Extension 15 SP7
Ссылки
- Link for SUSE-SU-2026:4148-1
- E-Mail link for SUSE-SU-2026:4148-1
- SUSE Security Ratings
- SUSE Bug 1267696
- SUSE Bug 1276764
- SUSE CVE CVE-2026-10805 page
- SUSE CVE CVE-2026-19685 page
Описание
A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.
Затронутые продукты
Ссылки
- CVE-2026-10805
- SUSE Bug 1267696
Описание
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.
Затронутые продукты
Ссылки
- CVE-2026-19685
- SUSE Bug 1276764