Junglewise Threat Intelligence

CVE-2026-63921: Linux Kernel traffic redirection in IPv6 VTI tunnel migration

CVE-2026-63921 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's IPv6 Virtual Tunnel Interface (VTI) could allow a local attacker to intercept network traffic. By moving a network tunnel between different isolated environments (containers), an attacker can manipulate how the system routes traffic, potentially redirecting data intended for another user or tenant to a device they control. This issue primarily affects multi-tenant environments like container hosts where users share the same underlying kernel.

Technical details

A vulnerability exists in the vti6_siocdevprivate() function in net/ipv6/ip6_vti.c due to the use of dev_net(dev) instead of the tunnel's creation namespace (t->net) during collision lookups. When a tunnel is migrated via IFLA_NET_NS_FD, an unprivileged user in the new namespace can trigger SIOCCHGTUNNEL to mutate the hash table of the original creation namespace. This allows an attacker to prepend a migrated tunnel to a hash bucket in the creation namespace, causing subsequent XFRM lookups to resolve to the attacker-controlled device. The exploit is reachable from an unprivileged user namespace and can lead to cross-tenant traffic interception on container hosts. The fix ensures lookups use the tunnel's original namespace and adds a CAP_NET_ADMIN check against the creation namespace's user namespace.

Affected products

  • Linux Linux Kernel v5.15+

Timeline

  • 2026-05-21: disclosed: Initial patch submission by Maoyi Xie
  • 2026-06-19: patched: Patch committed to stable tree by Greg Kroah-Hartman
  • 2026-07-19: advisory: CVE-2026-63921 published

References

Related threats