Junglewise Threat Intelligence

CVE-2026-72051: Linux kernel ip6_tunnel privilege escalation via changelink

CVE-2026-72051 · Severity: high · CVSS 8.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's IPv6 tunnel implementation contains a privilege escalation vulnerability in its changelink operation. An attacker with administrative capabilities in one network namespace but lacking them in another can modify tunnel configurations in a namespace where they lack authorization, potentially compromising network isolation and tunnel security.

Technical details

The vulnerability exists in the ip6_tnl_changelink() function in net/ipv6/ip6_tunnel.c, which can operate across two different network namespaces (netns). The rtnl changelink path checked CAP_NET_ADMIN capability only against dev_net(dev), allowing a caller privileged in one namespace to rewrite tunnels residing in another namespace where they lack privileges. The fix adds a call to rtnl_dev_link_net_capable() at the start of ip6_tnl_changelink() to enforce capability checks in the correct namespace before any attributes are parsed. The vulnerability requires local access to a network namespace and affects systems with IPv6 tunnels spanning multiple network namespaces.

Affected products

  • Linux Linux kernel Affects multiple versions; fixed in commit 2496fa0b7d180b3ad356b514e7ff93bb14e6140a upstream

Timeline

  • 2026-08-15: disclosed
  • 2026-06-12: patched: Patch committed upstream

References

Related threats