CVE-2026-72054

Source
https://cve.org/CVERecord?id=CVE-2026-72054
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72054.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72054
Downstream
Published
2026-08-15T05:52:10.679Z
Modified
2026-08-18T03:56:19.395922248Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
Details

In the Linux kernel, the following vulnerability has been resolved:

net: ipvti: require CAPNET_ADMIN in the device netns for changelink

vtichangelink() operates on at most two netns, devnet(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAPNETADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net.

Gate vtichangelink() on rtnldevlinknet_capable() at its top, before any attribute is parsed.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72054.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
895de9a3488abcdd186680f0af3cce7f2d4d4a6e
Fixed
1caf737e625143c6f23c32d2b747b1a3e42e5699
Fixed
32edf8aa297745226854eda2d96c0fac66c1bb15
Fixed
973ead9e565423642e4533e1547b5d2c0476fb03
Fixed
33fd93961557ec8e3e9958995b28684c5f949394
Fixed
6d8bc0dc99472d62c57c2a3d436e6ab408592bda
Fixed
9571af2eec8023af9a1671b7f2cd4ab400011724
Fixed
88b33ee458a6ca5fbef6c53b9dba772da69dab68
Fixed
95cceadbfd52d7239bd730afdda0655287d77425

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72054.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.15.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72054.json"