Описание
Security update for NetworkManager
This update for NetworkManager fixes the following issues:
Security fixes:
- CVE-2025-9615: Fixed non-admin user using others' certificates (bsc#1257359).
Other fixes:
- Accept localhost hostnames if static (bsc#1257366)
Список пакетов
openSUSE Leap 16.0
NetworkManager-1.52.0-160000.4.1
NetworkManager-bluetooth-1.52.0-160000.4.1
NetworkManager-branding-upstream-1.52.0-160000.4.1
NetworkManager-cloud-setup-1.52.0-160000.4.1
NetworkManager-config-server-1.52.0-160000.4.1
NetworkManager-devel-1.52.0-160000.4.1
NetworkManager-lang-1.52.0-160000.4.1
NetworkManager-ovs-1.52.0-160000.4.1
NetworkManager-pppoe-1.52.0-160000.4.1
NetworkManager-tui-1.52.0-160000.4.1
NetworkManager-wwan-1.52.0-160000.4.1
libnm0-1.52.0-160000.4.1
typelib-1_0-NM-1_0-1.52.0-160000.4.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1257359
- SUSE Bug 1257366
- SUSE CVE CVE-2025-9615 page
Описание
A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.
Затронутые продукты
openSUSE Leap 16.0:NetworkManager-1.52.0-160000.4.1
openSUSE Leap 16.0:NetworkManager-bluetooth-1.52.0-160000.4.1
openSUSE Leap 16.0:NetworkManager-branding-upstream-1.52.0-160000.4.1
openSUSE Leap 16.0:NetworkManager-cloud-setup-1.52.0-160000.4.1
Ссылки
- CVE-2025-9615
- SUSE Bug 1257359