Junglewise Threat Intelligence

CVE-2026-72055: Linux kernel ip6_vti privilege escalation via changelink

CVE-2026-72055 · Severity: high · CVSS 8.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's IPv6 virtual tunnel interface (ip6_vti) implementation fails to properly validate network administration privileges when modifying tunnel configuration. An attacker with administrative rights in one network namespace but not another can reconfigure tunnels in namespaces where they lack authorization, potentially disrupting network traffic or redirecting tunnel endpoints to compromise connected systems.

Technical details

The vulnerability is a privilege escalation in the vti6_changelink() function in net/ipv6/ip6_vti.c. The function operates across multiple network namespaces (dev_net(dev) and the tunnel link netns t->net) but the rtnl changelink path only checks CAP_NET_ADMIN against dev_net(dev). A caller with CAP_NET_ADMIN in dev_net(dev) but not in t->net can bypass the authorization check and reconfigure tunnels in the t->net namespace. The fix gates vti6_changelink() on rtnl_dev_link_net_capable() at the function entry point, before any attribute parsing. The vulnerability affects systems with network namespace support enabled and multiple network namespaces in use. Patches are available in the Linux stable tree.

Affected products

  • Linux Linux kernel Multiple versions (patches available in stable branches from linux-4.x onwards)

Timeline

  • 2026-06-12: disclosed: Vulnerability reported by Xiao Liang
  • 2026-07-24: patched: Patch committed to Linux stable tree by Greg Kroah-Hartman

References

Related threats