[Git][security-tracker-team/security-tracker][master] Add new batch of network-manager VPN plugins issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 16 19:45:04 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8d89d499 by Salvatore Bonaccorso at 2026-09-16T20:43:47+02:00
Add new batch of network-manager VPN plugins issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,23 @@
+CVE-2026-91841 [Incomplete fix of CVE-2018-10900]
+	- network-manager-vpnc <unfixed>
+	NOTE: https://gitlab.gnome.org/Archive/NetworkManager-vpnc/-/work_items/20
+	NOTE: https://blogs.gnome.org/mcatanzaro/2026/09/15/privilege-escalation-vulnerabilities-in-networkmanager-plugins/
+CVE-2026-91840 [username newline injection reaches a root password helper]
+	- network-manager-vpnc <unfixed>
+	NOTE: https://gitlab.gnome.org/Archive/NetworkManager-vpnc/-/work_items/19
+	NOTE: https://blogs.gnome.org/mcatanzaro/2026/09/15/privilege-escalation-vulnerabilities-in-networkmanager-plugins/
+CVE-2026-91839 [credential newline injection permits local root code execution]
+	- network-manager-fortisslvpn <removed>
+	NOTE: https://gitlab.gnome.org/Archive/NetworkManager-fortisslvpn/-/work_items/80
+	NOTE: https://blogs.gnome.org/mcatanzaro/2026/09/15/privilege-escalation-vulnerabilities-in-networkmanager-plugins/
+CVE-2026-91838 [profile data reaches root pppd pty shell]
+	- network-manager-sstp <unfixed>
+	NOTE: https://gitlab.gnome.org/GNOME/network-manager-sstp/-/work_items/67
+	NOTE: https://blogs.gnome.org/mcatanzaro/2026/09/15/privilege-escalation-vulnerabilities-in-networkmanager-plugins/
+CVE-2026-91837 [network-manager-iodine: Option confusion reaches iodine's pre-drop root shell]
+	- network-manager-iodine <unfixed>
+	NOTE: https://gitlab.gnome.org/GNOME/network-manager-iodine/-/work_items/4
+	NOTE: https://blogs.gnome.org/mcatanzaro/2026/09/15/privilege-escalation-vulnerabilities-in-networkmanager-plugins/
 CVE-2026-90038 [NFSD: Prevent client use-after-free during export state revocation]
 	- linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/2108de53568a64936a0da3e04d85c35df98d3fb6 (7.3-rc1)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8d89d499a43424915f66b11caf8eced2af4de45d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8d89d499a43424915f66b11caf8eced2af4de45d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/161c876e/attachment.htm>


More information about the debian-security-tracker-commits mailing list