Skip to content
VulniPulse
High7.1Red Hat Linux

High [CVE-2025-9615 +1] Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing wpa-enterprise server validation bypass (incomplete fix for CVE-2025-9615)

This high-severity Red Hat Linux advisory covers CVE-2025-9615 and CVE-2026-19685 affecting Red Hat Enterprise Linux 10, Red Hat package: networkmanager-adsl, Red Hat package: networkmanager-bluetooth.

CVE-2026-19685 Published Aug 24, 2026Updated by vendor Aug 24, 2026
Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties.

This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

This issue is limited to WPA-Enterprise (802.1X) network connections; open and WPA2-Personal (PSK) networks are not affected. Exploitation requires an unprivileged, active local user session holding the (commonly passwordless on desktop systems) settings.modify.own polkit permission; the flaw is not reachable from a remote or inactive SSH session.

NetworkManager is the sole affected component: wpa_supplicant/hostapd are downstream consumers that correctly use whatever ca_path directory they are handed and require no change. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Weakness: CWE-863. Affected Red Hat products: Red Hat Enterprise Linux 10.

Red Hat does not currently list a fixing RHSA for this CVE.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 3 hours ago·verify at source

Fixed versions

No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.

Official advisory · high-confidence parse· fetched 3 hours ago·verify at source

Mitigation checklist

Temporary workarounds
  • Upstream fix is public: NetworkManager rejects 802-1x.ca-path and 802-1x.phase2-ca-path on private connections (those with connection.permissions) and requires ca-cert or system-ca-certs instead. Fixed upstream in commit a8e87381 (MR 2513), shipped in NetworkManager 1.58.1 and later 1.60 development snapshots. Until the fixed package is installed, use system-wide 802.1X profiles rather than per-user private ones, or set 802-1x.system-ca-certs=yes so the compiled system CA path overrides any user-supplied ca-path.

Official advisory · high-confidence parse· fetched 3 hours ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.