Improper Preservation of Permissions Affecting networkmanager/networkmanager package, versions [,1.52.2)[1.53.0,1.57.1-dev)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0% (1st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-NETWORKMANAGERNETWORKMANAGER-15147106
  • published29 Jan 2026
  • disclosed12 Dec 2025
  • creditUnknown

Introduced: 12 Dec 2025

CVE-2025-9615  (opens in a new tab)
CWE-281  (opens in a new tab)

How to fix?

Upgrade networkmanager/networkmanager to version 1.52.2, 1.57.1-dev or higher.

Overview

Affected versions of this package are vulnerable to Improper Preservation of Permissions in the VPN plugins. An attacker can gain unauthorized access to files owned by other users by configuring network connections as a non-root user, which are then processed by the daemon running with elevated privileges.

Workaround

This vulnerability can be mitigated by enabling SELinux in targeted enforcing mode, which restricts unwanted permissions for processes.

CVSS Base Scores

version 4.0
version 3.1