Linuxsecurity
SUSE NetworkManager Vulnerabilities Lead to Important Local Privilege Escalation Fixes
Article Content
SUSE has released updates for NetworkManager addressing two critical vulnerabilities: CVE-2026-10805 and CVE-2026-19685. CVE-2026-10805 allows local privilege escalation through malformed MUD URLs in the dhclient backend, while CVE-2026-19685 permits a bypass of WPA-Enterprise server certificate validation due to missing user ownership checks for 802.1X directory properties. Both vulnerabilities affect SUSE Linux Micro versions 6.0 and 6.2. The patches are available via SUSE's recommended installation methods, including YaST and zypper. The vulnerabilities were published on June 4 and August 24, 2026, respectively. Security professionals are urged to apply the patches as soon as possible to mitigate risks. The updates are rated as important, indicating a significant threat to affected systems.
Key Points: • Two critical vulnerabilities in SUSE NetworkManager have been patched. • CVE-2026-10805 and CVE-2026-19685 affect SUSE Linux Micro versions 6.0 and 6.2. • Immediate patching is recommended to prevent potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.