Bug 2533692 - CVE-2026-91840 NetworkManager-vpnc: NetworkManager-vpnc: local privilege escalation to root via newline injection in VPN username [fedora-all] [NEEDINFO]
Summary: CVE-2026-91840 NetworkManager-vpnc: NetworkManager-vpnc: local privilege esca...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: NetworkManager-vpnc
Version: rawhide
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Michael Catanzaro
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["74e8e02b-9a7e-4b93-a69f-f...
Depends On:
Blocks: CVE-2026-91840
TreeView+ depends on / blocked
 
Reported: 2026-09-15 10:55 UTC by Vladimir Vasilev
Modified: 2026-09-30 21:12 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:
mcatanza: needinfo? (lkundrak)


Attachments (Terms of Use)

Description Vladimir Vasilev 2026-09-15 10:55:29 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A privilege escalation flaw was found in NetworkManager-vpnc, the vpnc VPN plugin for NetworkManager. nm-vpnc-service validates plugin-specific VPN configuration items for embedded newline characters, but omits the top-level NMSettingVpn user-name property from this check. This unvalidated username is later serialized verbatim into vpnc's configuration as an "Xauth username" directive. A local unprivileged user can create a VPN profile whose username contains a newline character followed by a "Password helper" directive, causing the root-privileged vpnc process to parse the injected directive and execute an attacker-chosen helper program with UID/EUID 0 when the malicious VPN connection is activated.

Comment 1 Michael Catanzaro 2026-09-16 12:54:40 UTC
This is a local privilege escalation in software that is installed by default, and archived upstream. Hi Lubomir, what do you want to do here? Add a downstream patch to fix the flaw, or add it to fedora-obsolete-packages?

I've removed the package from F45 default install, but it's still going to be around for all users who upgrade from previous Fedora releases unless we add an Obsoletes.

Comment 2 Fedora Admin user for bugzilla script actions 2026-09-30 21:12:57 UTC
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.


Note You need to log in before you can comment on or make changes to this bug.