3.3 CVE-2025-9615

Enriched by CISA
 

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.
https://nvd.nist.gov/vuln/detail/CVE-2025-9615

Categories

CWE-281 : Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended. This is resultant from errors that prevent the permissions from being preserved. Incorrect ACLs used when restoring backups from directories that use symbolic links. Automatic modification of permissions inherited from another file system. Permissions on backup file are created with defaults, possibly less secure than original file. File is made world-readable when being cloned.

References


 

AFFECTED (from MITRE)


Vendor Product Versions
Red Hat Red Hat Enterprise Linux 10
  • 1:1.56.0-1.el10 < * [unaffected]
Red Hat Red Hat Enterprise Linux 9
  • 1:1.54.3-2.el9 < * [unaffected]
Red Hat Red Hat Enterprise Linux 9
  • 1:1.54.3-2.el9 < * [unaffected]
Red Hat Red Hat Enterprise Linux 6
    Red Hat Red Hat Enterprise Linux 7
      Red Hat Red Hat Enterprise Linux 8
        Red Hat Red Hat OpenShift Container Platform 4
          © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

          CPE

          cpe start end


          REMEDIATION




          EXPLOITS


          Exploit-db.com

          id description date
          No known exploits

          POC Github

          Url
          No known exploits

          Other Nist (github, ...)

          Url
          No known exploits


          CAPEC


          Common Attack Pattern Enumerations and Classifications

          id description severity
          No entry