Hi,
The following vulnerability was published for network-manager.
CVE-2026-19685[0]:
| core: 802.1x: reject ca-path for private connections
Note this relates to the CVE-2025-9615 fix as the introducing commit
is part of the series.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-19685
https://www.cve.org/CVERecord?id=CVE-2026-19685
[1] https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2513
[2] https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/a8e87381a3e70060abd721d9a347f42b2ba68e6e
Regards,
Salvatore