Description
In the Linux kernel, the following vulnerability has been resolved:

net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink

vti6_changelink() operates on at most two netns, dev_net(dev) and the
tunnel link netns t->net. They differ once the device is created in or
moved to a netns other than the one the request runs in. The rtnl
changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a
caller privileged there but not in t->net can rewrite a tunnel that
lives in t->net.

Gate vti6_changelink() on rtnl_dev_link_net_capable() at its top,
before any attribute is parsed.
Published: 2026-08-15
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

vti6_changelink() allows a caller with CAP_NET_ADMIN on the device’s net namespace to change the attributes of a tunnel that resides in a different net namespace, because the capability check only verifies the caller’s rights on the device namespace. This flaw enables an attacker who can interact with the device namespace but lacks rights in the tunnel’s namespace to rewrite tunnel parameters without proper authorization, potentially redirecting traffic or escalating privileges in the network stack.

Affected Systems

All versions of the Linux kernel that have not yet applied the patch documented in the provided kernel commit references. The vulnerability affects the net/ip6_vti subsystem across all distributions that ship the affected kernel code.

Risk and Exploitability

The vulnerability is a local or privileged escalation flaw; it requires the attacker to run within a context that has CAP_NET_ADMIN on the device namespace but not on the tunnel namespace. No exploit has been publicly documented and the EPSS score is not available, suggesting limited exploitation evidence. The flaw is not yet listed in CISA’s KEV catalog. Because the required capability is non‑trivial, the risk is moderate, but any system that operates ip6_vti tunnels should treat the issue as significant.

Generated by OpenCVE AI on August 15, 2026 at 08:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the kernel to a version that incorporates the fix from the referenced commit or upgrade to a distribution kernel that includes the patch.
  • If a kernel upgrade cannot be performed immediately, remove or restrict the CAP_NET_ADMIN capability from processes in the device’s network namespace to prevent unauthorized tunnel modification.; this is a temporary workaround.
  • Disable or relocate ip6_vti tunnels that are not needed so that only trusted processes in the appropriate namespace can manage them.

Generated by OpenCVE AI on August 15, 2026 at 08:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink vti6_changelink() operates on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net. Gate vti6_changelink() on rtnl_dev_link_net_capable() at its top, before any attribute is parsed.
Title net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-15T05:52:11.413Z

Reserved: 2026-08-09T03:40:39.903Z

Link: CVE-2026-72055

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:14.890

Modified: 2026-08-15T06:21:14.890

Link: CVE-2026-72055

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T08:45:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control