Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
NetworkManager is a system network service that manages network devices
and connections.
It was discovered that NetworkManager would set device MTUs based on MTU
values received in IPv6 RAs (Router Advertisements), without sanity
checking the MTU value first. A remote attacker could exploit this flaw to
create a denial of service attack, by sending a specially crafted IPv6 RA
packet to disturb IPv6 communication. (CVE-2015-0272)
A flaw was found in the way NetworkManager handled router advertisements.
An unprivileged user on a local network could use IPv6 Neighbor Discovery
ICMP to broadcast a non-route with a low hop limit, causing machines to
lower the hop limit on existing IPv6 routes. If this limit is small enough,
IPv6 packets would be dropped before reaching the final destination.
(CVE-2015-2924)
The network-manager-applet and NetworkManager-libreswan packages have been
upgraded to upstream versions 1.0.6, and provide a number of bug fixes and
enhancements over the previous versions. (BZ#1177582, BZ#1243057)
Bugs:
* It was not previously possible to set the Wi-Fi band to the "a" or "bg"
values to lock to a specific frequency band. NetworkManager has been fixed,
and it now sets the wpa_supplicant's "freq_list" option correctly, which
enables proper Wi-Fi band locking. (BZ#1254461)
* NetworkManager immediately failed activation of devices that did not have
a carrier early in the boot process. The legacy network.service then
reported activation failure. Now, NetworkManager has a grace period during
which it waits for the carrier to appear. Devices that have a carrier down
for a short time on system startup no longer cause the legacy
network.service to fail. (BZ#1079353)
* NetworkManager brought down a team device if the teamd service managing
it exited unexpectedly, and the team device was deactivated. Now,
NetworkManager respawns the teamd instances that disappear and is able to
recover from a teamd failure avoiding disruption of the team device
operation. (BZ#1145988)
* NetworkManager did not send the FQDN DHCP option even if host name was
set to FQDN. Consequently, Dynamic DNS (DDNS) setups failed to update the
DNS records for clients running NetworkManager. Now, NetworkManager sends
the FQDN option with DHCP requests, and the DHCP server is able to create
DNS records for such clients. (BZ#1212597)
* The command-line client was not validating the vlan.flags property
correctly, and a spurious warning message was displayed when the nmcli tool
worked with VLAN connections. The validation routine has been fixed, and
the warning message no longer appears. (BZ#1244048)
* NetworkManager did not propagate a media access control (MAC) address
change from a bonding interface to a VLAN interface on top of it.
Consequently, a VLAN interface on top of a bond used an incorrect MAC
address. Now, NetworkManager synchronizes the addresses correctly.
(BZ#1264322)
Enhancements:
* IPv6 Privacy extensions are now enabled by default. NetworkManager checks
the per-network configuration files, NetworkManager.conf, and then falls
back to "/proc/sys/net/ipv6/conf/default/use_tempaddr" to determine and set
IPv6 privacy settings at device activation. (BZ#1187525)
* The NetworkManager command-line tool, nmcli, now allows setting the
wake-on-lan property to 0 ("none", "disable", "disabled"). (BZ#1260584)
* NetworkManager now provides information about metered connections.
(BZ#1200452)
* NetworkManager daemon and the connection editor now support setting the
Maximum Transmission Unit (MTU) of a bond. It is now possible to change MTU
of a bond interface in a GUI. (BZ#1177582, BZ#1177860)
* NetworkManager daemon and the connection editor now support setting the
MTU of a team, allowing to change MTU of a teaming interface. (BZ#1255927)
NetworkManager users are advised to upgrade to these updated packages,
which correct these issues and add these enhancements.
https://access.redhat.com/security/cve/CVE-2015-0272 https://access.redhat.com/security/cve/CVE-2015-2924 https://access.redhat.com/security/updates/classification/#moderate
Red Hat Enterprise Linux Client (v. 7):
Source:
ModemManager-1.1.0-8.git20130913.el7.src.rpm
NetworkManager-1.0.6-27.el7.src.rpm
NetworkManager-libreswan-1.0.6-3.el7.src.rpm
network-manager-applet-1.0.6-2.el7.src.rpm
x86_64:
ModemManager-1.1.0-8.git20130913.el7.x86_64.rpm
ModemManager-debuginfo-1.1.0-8.git20130913.el7.i686.rpm
ModemManager-debuginfo-1.1.0-8.git20130913.el7.x86_64.rpm
ModemManager-glib-1.1.0-8.git20130913.el7.i686.rpm
ModemManager-glib-1.1.0-8.git20130913.el7.x86_64.rpm
NetworkManager-1.0.6-27.el7.x86_64.rpm
NetworkManager-adsl-1.0.6-27.el7.x86_64.rpm
NetworkManager-bluetooth-1.0.6-27.el7.x86_64.rpm
NetworkManager-debuginfo-1.0.6-27.el7.i686.rpm
NetworkManager-debuginfo-1.0.6-27.el7.x86_64.rpm
NetworkManager-glib-1.0.6-27.el7.i686.rpm
NetworkManager-glib-1.0.6-27.el7.x86_64.rpm
NetworkManager-libnm-1.0.6-27.el7.i686.rpm
NetworkManager-libnm-1.0.6-27.el7.x86_64.rpm
NetworkManager-libreswan-1.0.6-3.el7.x86_64.rpm
NetworkManager-libreswan-debuginfo-1.0.6-3.el7.x86_64.rpm
NetworkManager-libreswan-gnome-1.0.6-3.el7.x86_64.rpm
NetworkManager-team-1.0.6-27.el7.x86_64.rpm
NetworkManager-tui-1.0.6-27.el7.x86_64.rpm
NetworkManager-wifi-1.0.6-27.el7.x86_64.rpm
NetworkManager-wwan-1.0.6-27.el7.x86_64.rpm
libnm-gtk-1.0.6-2.el7.i686.rpm
Read the Full Advisory
Updated NetworkManager packages that fix two security issues, several bugs,and add various enhancements are now available for Red Hat EnterpriseLinux 7.Red Hat Product Security has rated this update as having Moderate securityimpact. Common Vulnerability Scoring System (CVSS) base scores, which givedetailed severity ratings, are available for each vulnerability from theCVE links in the References section.
Red Hat Enterprise Linux Client (v. 7) - x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Server (v. 7) - aarch64, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - aarch64, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64
918692 - PIN/Password dialog for Mobile Broadband forces user to enter password, even if it's not needed
1062301 - NetworkManager should provide a way to reload a configuration and to refresh resolv.conf if necessary
1139536 - [RFE] Improve handling of DEVICE and HWADDR in nm-connection-editor
1141417 - Persistent wake on lan across reboot
1168388 - veth device goes down when ipv4 dhcp lease expires
1168657 - nmcli hangs when deleting profile two times
1182575 - [nmcli] Can't add certificate blob via nmcli as description states
1183015 - ipv6.method shared prevents connection from being upped
1183444 - Attaching a team device to a bridge doesn't work.
1187525 - Enable privacy extensions by default
1192132 - CVE-2015-0272 kernel/NetworkManager: remote DoS using IPv6 RA with bogus MTU
1200451 - feature request: Indicate 2ghz and 5ghz wifi device capabilities
1200452 - feature request: provide information about metered connections
1201497 - [PATCH] fix a configure-and-quit=yes bug when DHCP client ID is set and hostname is not given
1207730 - Continuous IPv6 router solicitation loop
1209902 - CVE-2015-2924 NetworkManager: denial of service (DoS) attack against IPv6 network stacks due to improper handling of Router Advertisements
1211133 - high cpu use with many IPv6 cloned routes
1211859 - _nl_get_vtable: assertion 'vtable.handle' failed
1229471 - [bluez5] add DUN support to nm-connection-editor
1238840 - libreswan vpn is not working
Get the latest Linux and open source security news straight to your inbox.