Bug 26713 - networkmanager new security issue CVE-2020-10754
Summary: networkmanager new security issue CVE-2020-10754
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Assignee: QA Team
QA Contact: Sec team
Whiteboard: MGA7-64-OK
Keywords: validated_update
Blocks: 26673
Reported: 2020-06-01 21:34 CEST by David Walser
Modified: 2020-12-15 17:03 CET (History)
6 users (show)

Source RPM: networkmanager-1.18.6-1.2.mga7.src.rpm
Description David Walser 2020-06-01 21:34:47 CEST
Fedora has issued an advisory today (June 1):

The issue is fixed upstream in 1.18.8.
Comment 1 Lewis Smith 2020-06-02 21:16:12 CEST
Assigning to wally as registered maintainer, CC'ing Olav who also does it.

Comment 2 Jani Välimaa 2020-06-05 21:04:27 CEST
Pushed networkmanager-1.18.8-1.mga7 to core/updates_testing.

It also includes fixes for bug 26673.
David Walser 2020-06-06 18:08:49 CEST

Comment 3 David Walser 2020-06-06 18:19:29 CEST
type: security
subject: Updated networkmanager packages fix security vulnerability
 - CVE-2020-10754
     - networkmanager-1.18.8-1.mga7
     - networkmanager-applet-1.8.24-1.mga7
     - gnome-control-center-3.32.1-2.2.mga7
     - gnome-shell-3.32.1-2.1.mga7
description: |
  It was found that nmcli, a command line interface to NetworkManager did
  not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when
  creating a new profile. When a user connects to a network using this
  profile, the authentication does not happen and the connection is made
  insecurely (CVE-2020-10754).

  The networkmanager package has been updated to version 1.18.8, fixing
  this issue and other bugs.

  Also, the networkmanager-applet package has been updated to version
  1.8.24. It also adds support for connecting to WPA3 / SAE protected
  wireless networks.

  gnome-control-center and gnome-shell have been fixed to correctly
  identify the connections as WPA3.
 - https://bugs.mageia.org/show_bug.cgi?id=26673
 - https://bugs.mageia.org/show_bug.cgi?id=26713
 - https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/blob/nm-1-18/NEWS
 - https://gitlab.gnome.org/GNOME/network-manager-applet/-/blob/1.8.24/NEWS
 - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/SI4LWYUPI7M6B24ABADK24T77VF65B4A/

Comment 4 David Walser 2020-06-06 18:21:21 CEST
The networkmanager-applet, gnome-control-center, and gnome-shell stuff were already tested and OK'd in Bug 26673.

For the networkmanager package itself, the full set of RPMs is:
Comment 5 Brian Rockwell 2020-06-08 03:31:53 CEST
laptop a6 - wifi

Network tools I use are still functional and the system is connecting.

Comment 6 Thomas Andrews 2020-06-08 04:08:29 CEST
Installed and set up network manager on a 64-bit Plasma install with both wired and wifi connections. Was able to switch back and forth with no problems.

Using qarepo, I updated the packages from this bug, plus the additional packages from Bugs 26673 and 26674. All packages updated cleanly. Rebooted to make sure the new network manager was being used, and once again connections were stable and I was able to switch back and forth.

Looks OK here. Validating. Advisory information in Comment 3 and, I guess, Comment 4.
Comment 7 Mageia Robot 2020-06-15 09:55:56 CEST
An update for this issue has been pushed to the Mageia Updates repository.


Comment 8 David Walser 2020-12-15 17:03:54 CET
*** Bug 27829 has been marked as a duplicate of this bug. ***

