Description
In the Linux kernel, the following vulnerability has been resolved:

net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink

vti6_changelink() operates on at most two netns, dev_net(dev) and the
tunnel link netns t->net. They differ once the device is created in or
moved to a netns other than the one the request runs in. The rtnl
changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a
caller privileged there but not in t->net can rewrite a tunnel that
lives in t->net.

Gate vti6_changelink() on rtnl_dev_link_net_capable() at its top,
before any attribute is parsed.
Published: 2026-08-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

vti6_changelink() allows a caller with CAP_NET_ADMIN on the device’s net namespace to change the attributes of a tunnel that resides in a different net namespace, because the capability check only verifies the caller’s rights on the device namespace. This flaw enables an attacker who can interact with the device namespace but lacks rights in the tunnel’s namespace to rewrite tunnel parameters without proper authorization, potentially redirecting traffic or escalating privileges in the network stack.

Affected Systems

All versions of the Linux kernel that have not yet applied the patch documented in the provided kernel commit references. The vulnerability affects the net/ip6_vti subsystem across all distributions that ship the affected kernel code.

Risk and Exploitability

The vulnerability is a local or privileged escalation flaw; it requires the attacker to run within a context that has CAP_NET_ADMIN on the device namespace but not on the tunnel’s namespace. No exploit has been publicly documented and the EPSS score is < 1%, indicating a low to modest likelihood of exploitation. The flaw is not yet listed in CISA’s KEV catalog. Because the required capability is non‑trivial, the risk is moderate, but any system that operates ip6_vti tunnels should treat the issue as significant. The CVSS base score of 8.8 indicates a high severity.

Generated by OpenCVE AI on August 18, 2026 at 03:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the kernel to a version that incorporates the fix from the referenced commit or upgrade to a distribution kernel that includes the patch.
  • If a kernel upgrade cannot be performed immediately, remove or restrict the CAP_NET_ADMIN capability from processes in the device’s network namespace to prevent unauthorized tunnel modification; this is a temporary workaround.
  • Disable or relocate ip6_vti tunnels that are not needed so that only trusted processes in the appropriate namespace can manage them.

Generated by OpenCVE AI on August 18, 2026 at 03:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-270
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Sat, 15 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink vti6_changelink() operates on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net. Gate vti6_changelink() on rtnl_dev_link_net_capable() at its top, before any attribute is parsed.
Title net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:39:52.104Z

Reserved: 2026-08-09T03:40:39.903Z

Link: CVE-2026-72055

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:14.890

Modified: 2026-08-17T06:18:03.760

Link: CVE-2026-72055

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72055 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T04:00:10Z

Weaknesses
  • CWE-270

    Privilege Context Switching Error