Executive brief
The Linux kernel's VXLAN (Virtual Extensible LAN) networking driver allows a privileged user in one network namespace to reconfigure VXLAN tunnels whose underlying network interfaces are in a different namespace. This missing permission check permits unauthorized modifications to tunnel configuration and socket management across namespace boundaries, potentially allowing network isolation bypass or unauthorized tunnel tampering by privileged-but-restricted users.
Technical details
The vulnerability is a missing authorization check in the VXLAN changelink() handler (vxlan_changelink()) in the Linux kernel's drivers/net/vxlan/vxlan_core.c file. The root cause is that the rtnl changelink path only validates CAP_NET_ADMIN permissions against the device's network namespace (dev_net(dev)), but VXLAN devices maintain a separate "sticky" underlay namespace (vxlan->net). An attacker with CAP_NET_ADMIN in the device namespace but not in the underlay namespace can call vxlan_changelink() to reconfigure the VXLAN device, modify socket settings, and operate on network resources in the underlay namespace without proper authorization. The fix adds a call to rtnl_dev_link_net_capable() at the top of vxlan_changelink() to verify the caller has the required capability in both the device and underlay namespaces before processing any configuration changes.
Affected products
- Linux Linux kernel multiple versions (patched in stable branches via commit 0aa580a8bbbed2507b4582a1f0ef581d480d06ed and others)
Timeline
- 2026-08-12: disclosed: Published on NVD
- 2026-07-16: patched: Fix committed upstream; backported to stable kernels by 2026-08-19