Description
A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.
Problem types
Improper Preservation of Permissions
Product status
Timeline
| 2025-08-28: | Reported to Red Hat. |
| 2025-12-12: | Made public. |
References
access.redhat.com/security/cve/CVE-2025-9615
bugzilla.redhat.com/show_bug.cgi?id=2391503 (RHBZ#2391503)
gitlab.freedesktop.org/...nager/NetworkManager/-/issues/1809
gitlab.freedesktop.org/...tworkManager/-/merge_requests/2324
gitlab.freedesktop.org/...tworkManager/-/merge_requests/2327