Executive brief
The Linux kernel's IPv6 virtual tunnel interface (ip6_vti) implementation fails to properly validate network administration privileges when modifying tunnel configuration. An attacker with administrative rights in one network namespace but not another can reconfigure tunnels in namespaces where they lack authorization, potentially disrupting network traffic or redirecting tunnel endpoints to compromise connected systems.
Technical details
The vulnerability is a privilege escalation in the vti6_changelink() function in net/ipv6/ip6_vti.c. The function operates across multiple network namespaces (dev_net(dev) and the tunnel link netns t->net) but the rtnl changelink path only checks CAP_NET_ADMIN against dev_net(dev). A caller with CAP_NET_ADMIN in dev_net(dev) but not in t->net can bypass the authorization check and reconfigure tunnels in the t->net namespace. The fix gates vti6_changelink() on rtnl_dev_link_net_capable() at the function entry point, before any attribute parsing. The vulnerability affects systems with network namespace support enabled and multiple network namespaces in use. Patches are available in the Linux stable tree.
Affected products
- Linux Linux kernel Multiple versions (patches available in stable branches from linux-4.x onwards)
Timeline
- 2026-06-12: disclosed: Vulnerability reported by Xiao Liang
- 2026-07-24: patched: Patch committed to Linux stable tree by Greg Kroah-Hartman