Impact
The Linux kernel network subsystem fails to enforce CAP_NET_ADMIN on the network namespace of a tunnel device when changing link parameters. A caller that holds capability in the device’s own namespace but not in the tunnel’s namespace can modify the tunnel configuration, enabling unauthorized network traffic or disruption.
Affected Systems
All Linux kernel versions deployable on standard distributions are potentially affected. The flaw resides in the ipip driver and affects system administrators and privileged users capable of invoking rtnl link changes.
Risk and Exploitability
The vulnerability provides a privilege‑escalation vector that can be leveraged by local or network‑level attackers with capability CAP_NET_ADMIN in the device’s namespace. While no CVSS or EPSS metrics are currently published, the impact on network isolation makes it significant, and the fix is already available in recent kernel releases. The issue is not yet listed in CISA KEV.
OpenCVE Enrichment