This update for NetworkManager fixes the following issues:
Security fixes:
- CVE-2025-9615: Fixed non-admin user using others' certificates (bsc#1257359).
Other fixes:
- Accept localhost hostnames if static (bsc#1257366)
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-896=1
- openSUSE Leap 16.0:
NetworkManager-1.52.0-160000.4.1
NetworkManager-bluetooth-1.52.0-160000.4.1
NetworkManager-branding-upstream-1.52.0-160000.4.1
NetworkManager-cloud-setup-1.52.0-160000.4.1
NetworkManager-config-server-1.52.0-160000.4.1
NetworkManager-devel-1.52.0-160000.4.1
NetworkManager-lang-1.52.0-160000.4.1
NetworkManager-ovs-1.52.0-160000.4.1
NetworkManager-pppoe-1.52.0-160000.4.1
NetworkManager-tui-1.52.0-160000.4.1
NetworkManager-wwan-1.52.0-160000.4.1
libnm0-1.52.0-160000.4.1
typelib-1_0-NM-1_0-1.52.0-160000.4.1
* bsc#1257359
* bsc#1257366
References:
* https://www.suse.com/security/cve/CVE-2025-9615.html
Get the latest Linux and open source security news straight to your inbox.