PatchSiren

Fedora CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Fedora CVE published 2026-09-14

CVE-2026-19624

A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security association is established, resulting in local privilege escalation. This flaw in NetworkManager-l2tp allows the execution of arbitrary commands as root, potentially leading to a full system compromise. The vulnerability [truncated]