CVE-2026-72054

Summary

In the Linux kernel, the following vulnerability has been resolved:

net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink

vti_changelink() operates on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net.

Gate vti_changelink() on rtnl_dev_link_net_capable() at its top, before any attribute is parsed.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux895de9a3488abcdd186680f0af3cce7f2d4d4a6e < 1caf737e625143c6f23c32d2b747b1a3e42e5699affected
LinuxLinux895de9a3488abcdd186680f0af3cce7f2d4d4a6e < 32edf8aa297745226854eda2d96c0fac66c1bb15affected
LinuxLinux895de9a3488abcdd186680f0af3cce7f2d4d4a6e < 973ead9e565423642e4533e1547b5d2c0476fb03affected
LinuxLinux895de9a3488abcdd186680f0af3cce7f2d4d4a6e < 33fd93961557ec8e3e9958995b28684c5f949394affected
LinuxLinux895de9a3488abcdd186680f0af3cce7f2d4d4a6e < 6d8bc0dc99472d62c57c2a3d436e6ab408592bdaaffected
LinuxLinux895de9a3488abcdd186680f0af3cce7f2d4d4a6e < 9571af2eec8023af9a1671b7f2cd4ab400011724affected
LinuxLinux895de9a3488abcdd186680f0af3cce7f2d4d4a6e < 88b33ee458a6ca5fbef6c53b9dba772da69dab68affected
LinuxLinux895de9a3488abcdd186680f0af3cce7f2d4d4a6e < 95cceadbfd52d7239bd730afdda0655287d77425affected
LinuxLinux3.15affected
LinuxLinux0 < 3.15unaffected
LinuxLinux5.10.261 <= 5.10.*unaffected
LinuxLinux5.15.212 <= 5.15.*unaffected
LinuxLinux6.1.178 <= 6.1.*unaffected
LinuxLinux6.6.145 <= 6.6.*unaffected
LinuxLinux6.12.97 <= 6.12.*unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References