Junglewise Threat Intelligence

CVE-2026-68432: Linux kernel VXLAN privilege escalation in changelink

CVE-2026-68432 · Severity: high · CVSS 8.8 · Published 2026-08-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's VXLAN (Virtual Extensible LAN) networking driver allows a privileged user in one network namespace to reconfigure VXLAN tunnels whose underlying network interfaces are in a different namespace. This missing permission check permits unauthorized modifications to tunnel configuration and socket management across namespace boundaries, potentially allowing network isolation bypass or unauthorized tunnel tampering by privileged-but-restricted users.

Technical details

The vulnerability is a missing authorization check in the VXLAN changelink() handler (vxlan_changelink()) in the Linux kernel's drivers/net/vxlan/vxlan_core.c file. The root cause is that the rtnl changelink path only validates CAP_NET_ADMIN permissions against the device's network namespace (dev_net(dev)), but VXLAN devices maintain a separate "sticky" underlay namespace (vxlan->net). An attacker with CAP_NET_ADMIN in the device namespace but not in the underlay namespace can call vxlan_changelink() to reconfigure the VXLAN device, modify socket settings, and operate on network resources in the underlay namespace without proper authorization. The fix adds a call to rtnl_dev_link_net_capable() at the top of vxlan_changelink() to verify the caller has the required capability in both the device and underlay namespaces before processing any configuration changes.

Affected products

  • Linux Linux kernel multiple versions (patched in stable branches via commit 0aa580a8bbbed2507b4582a1f0ef581d480d06ed and others)

Timeline

  • 2026-08-12: disclosed: Published on NVD
  • 2026-07-16: patched: Fix committed upstream; backported to stable kernels by 2026-08-19

References

Related threats