安全公告详情

NS-SA-2026-0018

2026-03-04 16:02:56

简介

important: libnl3/NetworkManager security update

严重级别

important

主题

An update for libnl3/NetworkManager is now available for NewStart CGSL MAIN 6.06.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

libnl3:
NetworkManager:


Security Fix(es):
libnl3: An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32255299.(CVE-2017-0386)
libnl3: bugfix
NetworkManager: m-applet.conf in GNOME NetworkManager before 0.7.0.99 contains an incorrect deny setting, which allows local users to discover (1) network connection passwords and (2) pre-shared keys via calls to the GetSecrets method in the dbus request handler.(CVE-2009-0365)
NetworkManager: GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network connections of arbitrary users via unspecified vectors related to org.freedesktop.NetworkManagerUserSettings and at_console.(CVE-2009-0578)
NetworkManager: DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by modifying properties, as demonstrated by properties of the (1) DeviceKit-Power, (2) NetworkManager, and (3) ModemManager services.(CVE-2010-1172)
NetworkManager: The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0.8.999-3.git20110526 in Fedora 15 creates a log entry containing a certificate password, which allows local users to obtain sensitive information by reading a log file(CVE-2011-1943)
NetworkManager: GNOME NetworkManager before 0.8.6 does not properly enforce the auth_admin element in PolicyKit, which allows local users to bypass intended wireless network sharing restrictions via unspecified vectors.(CVE-2011-2176)
NetworkManager: Incomplete blacklist vulnerability in the svEscape function in settings/plugins/ifcfg-rh/shvar.c in the ifcfg-rh plug-in for GNOME NetworkManager 0.9.1, 0.9.0, 0.8.1, and possibly other versions, when PolicyKit is configured to allow users to create new connections, allows local users to execute arbitrary commands via a newline character in the name for a new network connection, which is not properly handled when writing to the ifcfg file.(CVE-2011-3364)
NetworkManager: It was discovered that systemd-network does not correctly keep track of a buffer size when constructing DHCPv6 packets. This flaw may lead to an integer underflow that can be used to produce an heap-based buffer overflow. A malicious host on the same network segment as the victim's one may advertise itself as a DHCPv6 server and exploit this flaw to cause a Denial of Service or potentially gain code execution on the victim's machine.(CVE-2018-15688)
NetworkManager: An exploitable denial of service vulnerability exists in systemd which does not fully implement RFC3203, as it does not support authentication of FORCERENEW packets. A specially crafted DHCP FORCERENEW packet can cause a system, running the DHCP client, to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHPACK packets to reconfigure the system with arbitrary network settings.(CVE-2020-13529)
NetworkManager: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 6.06.01B6.

影响组件

  • libnl3
  • NetworkManager

影响产品

  • CGSL MAIN 6.06 (SP)

更新包

{"fix":[{"product":"CGSL MAIN 6.06 (SP)","pkgs":[{"binary":["libnl3-3.5.0-1.zncgsl6.x86_64.rpm","libnl3-cli-3.5.0-1.zncgsl6.x86_64.rpm","libnl3-devel-3.5.0-1.zncgsl6.x86_64.rpm"],"source":"libnl3-3.5.0-1.zncgsl6.src.rpm"},{"binary":["NetworkManager-1.36.0-9.0.1.zncgsl6_6.t1.0.x86_64.rpm","NetworkManager-libnm-1.36.0-9.0.1.zncgsl6_6.t1.0.x86_64.rpm","NetworkManager-team-1.36.0-9.0.1.zncgsl6_6.t1.0.x86_64.rpm","NetworkManager-tui-1.36.0-9.0.1.zncgsl6_6.t1.0.x86_64.rpm"],"source":"NetworkManager-1.36.0-9.0.1.zncgsl6_6.t1.0.src.rpm"}]}]}

CVE

参考