CVE-2026-72061

Summary

In the Linux kernel, the following vulnerability has been resolved:

net: sit: require CAP_NET_ADMIN in the device netns for changelink

ipip6_changelink() operates on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net.

Gate ipip6_changelink() on rtnl_dev_link_net_capable() at its top, before any attribute is parsed. sit was the one tunnel type not covered by the recent series that added this check to the other changelink() handlers.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux5e6700b3bf98fe98d630bf9c939ad4c85ce95592 < cb41b308e9d867725d965b291dd085028e36a480affected
LinuxLinux5e6700b3bf98fe98d630bf9c939ad4c85ce95592 < c5a0ae895432596b2f464172da8218e2d84e2932affected
LinuxLinux5e6700b3bf98fe98d630bf9c939ad4c85ce95592 < 7d139dec96691cde96cb40ed293e2d13d994fb4faffected
LinuxLinux5e6700b3bf98fe98d630bf9c939ad4c85ce95592 < 388ccffbd2e7e5e4271f291085a7451865705305affected
LinuxLinux5e6700b3bf98fe98d630bf9c939ad4c85ce95592 < c0ea1aedb37bb979e864ed7787975434bbd9db73affected
LinuxLinux5e6700b3bf98fe98d630bf9c939ad4c85ce95592 < 3118e97dae533fb45964b87bbed1801afcff7c65affected
LinuxLinux5e6700b3bf98fe98d630bf9c939ad4c85ce95592 < 99ae3248b33df94201915d9c32e7470cdf08cfcdaffected
LinuxLinux5e6700b3bf98fe98d630bf9c939ad4c85ce95592 < 27ccb68e7cccead5d8c611665a45d23032d468b3affected
LinuxLinux3.11affected
LinuxLinux0 < 3.11unaffected
LinuxLinux5.10.261 <= 5.10.*unaffected
LinuxLinux5.15.212 <= 5.15.*unaffected
LinuxLinux6.1.178 <= 6.1.*unaffected
LinuxLinux6.6.145 <= 6.6.*unaffected
LinuxLinux6.12.97 <= 6.12.*unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References