3.3

CVE-2025-9615

Networkmanager: networkmanager file access

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 10
Default Statusaffected
Version 1:1.56.0-1.el10
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 9
Default Statusaffected
Version 1:1.54.3-2.el9
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 9
Default Statusaffected
Version 1:1.54.3-2.el9
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 6
Default Statusunknown
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 7
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 8
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat OpenShift Container Platform 4
Default Statusaffected
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.057
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 3.3 1.8 1.4
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-281 Improper Preservation of Permissions

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

https://access.redhat.com/security/cve/CVE-2025-9615
https://bugzilla.redhat.com/show_bug.cgi?id=2391503
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/issues/1809
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2324
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2327
https://access.redhat.com/errata/RHSA-2026:18142
https://access.redhat.com/errata/RHSA-2026:18597