CVE-2024-9050
Description
A local privilege escalation in NetworkManager-libreswan allows unprivileged users to inject arbitrary commands via unsanitized VPN configuration keys, achieving root-level code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A local privilege escalation in NetworkManager-libreswan allows unprivileged users to inject arbitrary commands via unsanitized VPN configuration keys, achieving root-level code execution.
A flaw in the libreswan client plugin for NetworkManager (NetworkManager-libreswan) fails to properly sanitize VPN configuration supplied by a local unprivileged user. The configuration uses a key-value format, and the plugin does not escape special characters, allowing values to be interpreted as keys [1],[2]. This injection vulnerability can be exploited through the leftupdown key, which specifies a callback executable command used to retrieve configuration settings back to NetworkManager. Since NetworkManager leverages Polkit to grant unprivileged users control over the system's network configuration, a malicious user can craft a configuration entry where the leftupdown value includes arbitrary commands [3],[4]. An attacker with local unprivileged access can exploit this flaw to execute arbitrary code as root, gaining full control over the affected system. Red Hat has released security updates for multiple RHEL versions (RHSA-2024:9555, RHSA-2024:8352, RHSA-2024:9556, RHSA-2024:8354) to address this vulnerability; affected users should apply the updates promptly [1],[2],[3],[4].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
5- osv-coords3 versionspkg:rpm/almalinux/NetworkManager-libreswanpkg:rpm/almalinux/NetworkManager-libreswan-gnomepkg:rpm/opensuse/NetworkManager-libreswan&distro=openSUSE%20Tumbleweed
< 1.2.10-7.el8_10+ 2 more
- (no CPE)range: < 1.2.10-7.el8_10
- (no CPE)range: < 1.2.10-7.el8_10
- (no CPE)range: < 1.2.24-1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
15- www.openwall.com/lists/oss-security/2024/10/25/1nvd
- access.redhat.com/errata/RHSA-2024:8312nvd
- access.redhat.com/errata/RHSA-2024:8338nvd
- access.redhat.com/errata/RHSA-2024:8352nvd
- access.redhat.com/errata/RHSA-2024:8353nvd
- access.redhat.com/errata/RHSA-2024:8354nvd
- access.redhat.com/errata/RHSA-2024:8355nvd
- access.redhat.com/errata/RHSA-2024:8356nvd
- access.redhat.com/errata/RHSA-2024:8357nvd
- access.redhat.com/errata/RHSA-2024:8358nvd
- access.redhat.com/errata/RHSA-2024:9555nvd
- access.redhat.com/errata/RHSA-2024:9556nvd
- access.redhat.com/security/cve/CVE-2024-9050nvd
- bugzilla.redhat.com/show_bug.cginvd
- www.openwall.com/lists/oss-security/2024/10/25/1nvd
News mentions
0No linked articles in our index yet.