CVE-2025-9615

NameCVE-2025-9615
DescriptionA flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
network-manager (PTS)bullseye1.30.6-1+deb11u1vulnerable
bookworm1.42.4-1+deb12u1vulnerable
trixie1.52.1-1vulnerable
forky1.54.3-1fixed
sid1.54.3-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
network-managersource(unstable)1.54.3-1

Notes

[trixie] - network-manager <ignored> (Intrusive and needs update across the VPN plugin ecosystem to keep them functional)
[bookworm] - network-manager <ignored> (Intrusive and needs update across the VPN plugin ecosystem to keep them functional)
[bullseye] - network-manager <ignored> (Intrusive and needs update across the VPN plugin ecosystem to keep them functional)
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2324
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/issues/1809 (not yet public)
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2327 (nm-1-52 backport)
The issue is in network-manager and the CVE associated with it. A patched
network-manager daemon will refuse to activating the private connections from plugins
without the fix. The VPN plugins need a corresponding update to keep then functional
when private connections are configured.

Search for package or bug name: Reporting problems