USN-8729-5: Linux kernel (AWS FIPS) vulnerabilities
USN-8729-5
It was discovered that NetworkManager did not properly restrict the ca-path and phase2-ca-path certificate authority settings for private (single-user) 802.1X network connections. An attacker could use this issue to point their own private 802.1X connection profile at a directory under their control, causing NetworkManager to trust an attacker-chosen certificate authority and potentially exposing network credentials via a rogue authentication server.
The collected bulletin did not provide a separate affected-products list. Check the original bulletin before making an exposure decision.
The publication date reported by the vendor.
We collected the advisory from the official source.
Our collector saw this advisory during a later source check.