rpm package
opensuse/NetworkManager-l2tp&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/NetworkManager-l2tp&distro=openSUSE%20Tumbleweed
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-75131 | Hig | 7.8 | < 1.52.6-1.1 | 1.52.6-1.1 | Sep 23, 2026 | NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains a privilege escalation vulnerability that allows local users with permission to create VPN connections to execute arbitrary code as root by injecting pppd options through a crafted VPN username. Attackers can embed a d | |
| CVE-2026-75883 | Med | 6.8 | < 1.52.6-1.1 | 1.52.6-1.1 | Sep 18, 2026 | The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf without checking the available space and without implementing outgoing PEAP fragmentation. Thus a ppp | |
| CVE-2025-9615 | Low | 3.3 | < 1.52.0-1.1 | 1.52.0-1.1 | Jan 26, 2026 | A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from th |
- affected < 1.52.6-1.1fixed 1.52.6-1.1
NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains a privilege escalation vulnerability that allows local users with permission to create VPN connections to execute arbitrary code as root by injecting pppd options through a crafted VPN username. Attackers can embed a d
- affected < 1.52.6-1.1fixed 1.52.6-1.1
The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf without checking the available space and without implementing outgoing PEAP fragmentation. Thus a ppp
- affected < 1.52.0-1.1fixed 1.52.0-1.1
A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from th