Executive brief
The Linux kernel's IPv6 tunnel implementation contains a privilege escalation vulnerability in its changelink operation. An attacker with administrative capabilities in one network namespace but lacking them in another can modify tunnel configurations in a namespace where they lack authorization, potentially compromising network isolation and tunnel security.
Technical details
The vulnerability exists in the ip6_tnl_changelink() function in net/ipv6/ip6_tunnel.c, which can operate across two different network namespaces (netns). The rtnl changelink path checked CAP_NET_ADMIN capability only against dev_net(dev), allowing a caller privileged in one namespace to rewrite tunnels residing in another namespace where they lack privileges. The fix adds a call to rtnl_dev_link_net_capable() at the start of ip6_tnl_changelink() to enforce capability checks in the correct namespace before any attributes are parsed. The vulnerability requires local access to a network namespace and affects systems with IPv6 tunnels spanning multiple network namespaces.
Affected products
- Linux Linux kernel Affects multiple versions; fixed in commit 2496fa0b7d180b3ad356b514e7ff93bb14e6140a upstream
Timeline
- 2026-08-15: disclosed
- 2026-06-12: patched: Patch committed upstream