In the Linux kernel, the following vulnerability has been resolved:
ip6: vti: Use ip6tnl.net in vti6changelink().
ip netns add ns1 ip netns add ns2 ip -n ns1 link add vti6test type vti6 remote ::1 local ::2 key 7 ip -n ns1 link set vti6test netns ns2 ip -n ns2 link set vti6_test type vti6 remote ::3 local ::4 key 9 ip netns del ns2 ip netns del ns1 [ 132.495484] ------------[ cut here ]------------ [ 132.497609] kernel BUG at net/core/dev.c:12376!
Commit 61220ab34948 ("vti6: Enable namespace changing") dropped NETIFFNETNSLOCAL from vti6 devices. A vti6 tunnel can then move through IFLANETNSFD. After the move dev_net(dev) points at the new netns while t->net stays at the creation netns.
vti6changelink() and vti6update() still use devnet(dev) and devnet(t->dev). They unlink from one per netns hash and relink into another. The creation netns is left with a stale entry. cleanup_net() of that netns later walks freed memory.
Reachable from an unprivileged user namespace (unshare --user --map-root-user --net). Cross tenant scope on container hosts.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63917.json",
"cna_assigner": "Linux"
}