CVE-2026-19624

NameCVE-2026-19624
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6498-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
network-manager-l2tp (PTS)bookworm1.20.8-1vulnerable
trixie1.20.20-2vulnerable
trixie (security)1.20.20-2+deb13u1fixed
forky1.52.4-1vulnerable
sid1.52.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
network-manager-l2tpsourcetrixie1.20.20-2+deb13u1DSA-6498-1
network-manager-l2tpsource(unstable)1.52.6-1

Notes

Fixed by: https://github.com/nm-l2tp/NetworkManager-l2tp/commit/3704d8c9d5e5f9ed1626a8ce7627a04247cea673 (1.52.6, 1.20.26)

Search for package or bug name: Reporting problems