CVE-2026-72136

Summary

In the Linux kernel, the following vulnerability has been resolved:

xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink

xfrmi_changelink() operates on at most two netns, dev_net(dev) and the interface link netns xi->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in xi->net can rewrite an interface that lives in xi->net.

Gate xfrmi_changelink() on rtnl_dev_link_net_capable() at its top, before any attribute is parsed.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxf203b76d78092faf248db3f851840fbecf80b40e < 04c1aa57d08471b1953bf27c84ac9b3d78d71831affected
LinuxLinuxf203b76d78092faf248db3f851840fbecf80b40e < bdfd1c21d90e628a58a9de79e024cdfcbedfa15caffected
LinuxLinuxf203b76d78092faf248db3f851840fbecf80b40e < 80ec68bba11f7f387c0e4099c2d7b2c84943eb99affected
LinuxLinuxf203b76d78092faf248db3f851840fbecf80b40e < e9c90756f10da334fb31552e52c61f1dba69f491affected
LinuxLinuxf203b76d78092faf248db3f851840fbecf80b40e < 37b61946d278c7deb0d40ba8f2b6fc0478d61dabaffected
LinuxLinuxf203b76d78092faf248db3f851840fbecf80b40e < 8ca2a19a987a7d1cb4c916ed9723a1c6993b4276affected
LinuxLinuxf203b76d78092faf248db3f851840fbecf80b40e < 3ba2b2ef7d6a63b190f15cfc2b4ba0fba59928eaaffected
LinuxLinuxf203b76d78092faf248db3f851840fbecf80b40e < 095515d89b19b6cc19dfcdc846f97403ed1ebce3affected
LinuxLinux4.19affected
LinuxLinux0 < 4.19unaffected
LinuxLinux5.10.261 <= 5.10.*unaffected
LinuxLinux5.15.212 <= 5.15.*unaffected
LinuxLinux6.1.178 <= 6.1.*unaffected
LinuxLinux6.6.145 <= 6.6.*unaffected
LinuxLinux6.12.97 <= 6.12.*unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References