:CrowHeartRainbow: on Nostr: i uSe lInUx bEcAuSe iT'S SeCuRe. > NetworkManager did not apply the private_user ...
i uSe lInUx bEcAuSe iT'S SeCuRe.
https://access.redhat.com/security/cve/cve-2026-19685> NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.
Published at
2026-08-24 18:50:25 UTCEvent JSON
{
"id": "656dc1ddb54c31e9f7c3dc2ca6d9b89c62a36d7ecea5a5fb93d012d84b20e0ea",
"pubkey": "86b397086a130510861dd58f255fadeee1c47815185fa3bb628a06b4d6af31ac",
"created_at": 1787597425,
"kind": 1,
"tags": [
[
"proxy",
"https://infosec.exchange/@cR0w/117151984890850771",
"web"
],
[
"proxy",
"https://infosec.exchange/users/cR0w/statuses/117151984890850771",
"activitypub"
],
[
"L",
"pink.momostr"
],
[
"l",
"pink.momostr.activitypub:https://infosec.exchange/users/cR0w/statuses/117151984890850771",
"pink.momostr"
],
[
"-"
]
],
"content": "i uSe lInUx bEcAuSe iT'S SeCuRe.\n\nhttps://access.redhat.com/security/cve/cve-2026-19685\n\n\u003e NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.",
"sig": "573affe935e334c2ba8d892b46d47f81a1b179cc53fa6b0385e5c4ea25ae6d64aa8386674ea021f723ae2e366381ff42c81641aa4a6b45545c7a1d1b1efd22aa"
}