CVE-2021-20297
published 2021-05-26CVE-2021-20297: A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.7th percentile
A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | network-manager | < network-manager 1.30.0-2 (bookworm) | network-manager 1.30.0-2 (bookworm) |
| fedoraproject | fedora | — | — |
| gnome | networkmanager | < 1.30.0 | 1.30.0 |
| gnome | networkmanager | — | — |
| network-manager_project | network-manager | >= 0 < 1.30.0-2 | 1.30.0-2 |
| network-manager_project | network-manager | >= 0 < 1.30.0-2 | 1.30.0-2 |
| network-manager_project | network-manager | >= 0 < 1.30.0-2 | 1.30.0-2 |
| network-manager_project | network-manager | >= 0 < 1.30.0-2 | 1.30.0-2 |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
NetworkManager vulnerability
vendor_ubuntu·2021-04-14
CVE-2021-20297 NetworkManager vulnerability
Title: NetworkManager vulnerability
Summary: NetworkManager could be made to crash if it received specially crafted
input.
It was discovered that NetworkManager incorrectly handled certain profiles.
A local attacker could possibly use this issue to cause NetworkManager to
crash, resulting in a denial of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
NetworkManager: Profile with match.path setting triggers crash
vendor_redhat·2021-03-25·CVSS 5.5
CVE-2021-20297 [MEDIUM] CWE-20 NetworkManager: Profile with match.path setting triggers crash
NetworkManager: Profile with match.path setting triggers crash
A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.
A flaw was found in NetworkManager. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.
Package: NetworkManager (Red Hat Enterprise Linux 6) - Not affected
Package: NetworkManager (Red Hat Enterprise Linux 7) - Not affected
Package: NetworkManager (Red Hat Enterprise Linux 9) - Not affected
Package: NetworkManager (Red Hat OpenShift Container Platform 4) - Will not fix
Debian
CVE-2021-20297: network-manager - A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path...
vendor_debian·2021·CVSS 5.5
CVE-2021-20297 [MEDIUM] CVE-2021-20297: network-manager - A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path...
A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 1.30.0-2)
bullseye: resolved (fixed in 1.30.0-2)
forky: resolved (fixed in 1.30.0-2)
sid: resolved (fixed in 1.30.0-2)
trixie: resolved (fixed in 1.30.0-2)
GHSA
GHSA-c9hx-hg53-g52p: A flaw was found in NetworkManager in versions before 1
ghsa_unreviewed·2022-05-24
CVE-2021-20297 [MEDIUM] CWE-20 GHSA-c9hx-hg53-g52p: A flaw was found in NetworkManager in versions before 1
A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.
OSV
CVE-2021-20297: A flaw was found in NetworkManager in versions before 1
osv·2021-05-26·CVSS 5.5
CVE-2021-20297 [MEDIUM] CVE-2021-20297: A flaw was found in NetworkManager in versions before 1
A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-05-26
Published