#1145199 network-manager: CVE-2026-19685

Package:
src:network-manager
Source:
src:network-manager
Submitter:
Salvatore Bonaccorso
Date:
2026-09-03 04:57:02 UTC
Severity:
normal
Tags:
#1145199#5
Date:
2026-08-23 19:14:25 UTC
From:
To:
Hi,

The following vulnerability was published for network-manager.

CVE-2026-19685[0]:
| core: 802.1x: reject ca-path for private connections

Note this relates to the CVE-2025-9615 fix as the introducing commit
is part of the series.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-19685
https://www.cve.org/CVERecord?id=CVE-2026-19685
[1] https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2513
[2] https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/a8e87381a3e70060abd721d9a347f42b2ba68e6e

Regards,
Salvatore

#1145199#12
Date:
2026-09-03 04:55:03 UTC
From:
To:
Hi Michael,

I think this fixes as well CVE-2026-19685 / #1145199 as it got a
backport in the 1.58 branch:
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/15aa1a8963ee014f5eb8306b305b158293c10643

So closing this one along as well.

Regards,
Salvatore