Description
In the Linux kernel, the following vulnerability has been resolved:

net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink

vti_changelink() operates on at most two netns, dev_net(dev) and the
tunnel link netns t->net. They differ once the device is created in or
moved to a netns other than the one the request runs in. The rtnl
changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a
caller privileged there but not in t->net can rewrite a tunnel that
lives in t->net.

Gate vti_changelink() on rtnl_dev_link_net_capable() at its top,
before any attribute is parsed.
Published: 2026-08-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vti_changelink function in the Linux kernel operates across the device’s network namespace and the tunnel’s own namespace, but it only checks for the CAP_NET_ADMIN capability in the device’s namespace. A process that holds CAP_NET_ADMIN in its own namespace can therefore modify a vti tunnel residing in a different namespace without having the same privilege there. This flaw allows the attacker to reconfigure the tunnel, redirect traffic or intercept data, effectively undermining the isolation provided by network namespaces.

Affected Systems

All Linux kernel builds before the patch that introduces the missing CAP_NET_ADMIN check are vulnerable. The affected product is the mainline Linux kernel, along with any derivatives that have not incorporated this fix. The vulnerability is present in the network stack’s vti tunnel implementation.

Risk and Exploitability

The vulnerability is local and requires the attacker to possess CAP_NET_ADMIN in at least one namespace. The EPSS score is below 1% and the issue is not listed in CISA KEV. The CVSS score of 8.8 indicates high severity. Nonetheless, the ability to alter tunnel configurations in multi‑tenant or containerized environments makes the risk moderate to high. Exploitation is straightforward for a process with administrative namespace privileges and can lead to significant network disruption or data exfiltration.

Generated by OpenCVE AI on August 18, 2026 at 02:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the kernel to the latest version that includes the mandatory CAP_NET_ADMIN check for vti_changelink
  • Limit the use of CAP_NET_ADMIN to the namespaces that require it using SELinux, AppArmor, or similar policy frameworks
  • Isolate critical network devices in dedicated namespaces and verify that vti tunnels do not span multiple namespaces
  • Enable audit logging for tun2/tun3 interface changelink events to detect unauthorized modifications

Generated by OpenCVE AI on August 18, 2026 at 02:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1220
References
Metrics threat_severity

None

threat_severity

Important


Mon, 17 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Sat, 15 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink vti_changelink() operates on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net. Gate vti_changelink() on rtnl_dev_link_net_capable() at its top, before any attribute is parsed.
Title net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:39:51.024Z

Reserved: 2026-08-09T03:40:39.903Z

Link: CVE-2026-72054

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:14.760

Modified: 2026-08-17T06:18:03.620

Link: CVE-2026-72054

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72054 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T02:15:04Z

Weaknesses
  • CWE-1220

    Insufficient Granularity of Access Control