Description
In the Linux kernel, the following vulnerability has been resolved:

net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink

ip6gre_changelink() and ip6erspan_changelink() operate on at most two
netns, dev_net(dev) and the tunnel link netns t->net. They differ once
the device is created in or moved to a netns other than the one the
request runs in. The rtnl changelink path checks CAP_NET_ADMIN only
against dev_net(dev), so a caller privileged there but not in t->net can
rewrite a tunnel that lives in t->net.

Gate both ops on rtnl_dev_link_net_capable() at their top, before any
attribute is parsed.
Published: 2026-08-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Linux kernel’s ip6_gre and ip6erspan changelink functions permits a process with CAP_NET_ADMIN in one network namespace to alter the configuration of a GRE or ERSPAN tunnel that resides in another namespace. The flaw arises because the kernel only checks the caller’s capability against the device’s own namespace, not the tunnel’s namespace. This allows the attacker to change tunnel parameters and potentially redirect traffic or disrupt connectivity, elevating their privileges within that namespace.

Affected Systems

Affected systems include all installations of the Linux kernel that have not incorporated the state‑of‑the‑art patch which adds the missing capability check. As no specific version list is provided, every kernel version released prior to the fix is considered vulnerable. The issue affects the generic Linux:Linux kernel product.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, but the extremely low EPSS score (<1%) and absence from the CISA KEV catalog suggest a low likelihood of widespread exploitation at present. The exploit requires a local attacker who already has CAP_NET_ADMIN privileges in a namespace—typically a root or privileged process—so the attack vector is local and limited to systems where namespace isolation is broken. Nevertheless, the missing authorization check could be abused to perform privileged network misconfigurations, warranting immediate remediation.

Generated by OpenCVE AI on August 18, 2026 at 05:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that contains the fix for the ip6_gre and ip6erspan changelink capability check.
  • Restrict CAP_NET_ADMIN to trusted users or processes so that only authorized entities can manipulate network namespaces.
  • Audit applications or scripts that move network devices across namespaces, verifying that they operate with appropriate privileges and that the host kernel enforces namespace boundary checks.

Generated by OpenCVE AI on August 18, 2026 at 05:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-266
References
Metrics threat_severity

None

threat_severity

Important


Mon, 17 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 17 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Sat, 15 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink ip6gre_changelink() and ip6erspan_changelink() operate on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net. Gate both ops on rtnl_dev_link_net_capable() at their top, before any attribute is parsed.
Title net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:39:48.851Z

Reserved: 2026-08-09T03:40:39.902Z

Link: CVE-2026-72052

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:14.523

Modified: 2026-08-17T06:18:03.330

Link: CVE-2026-72052

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72052 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T06:00:04Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment