Executive brief
The Linux kernel's SIT (Simple Internet Transition) tunnel implementation failed to enforce proper permission checks when modifying tunnel configuration across network namespaces. An unprivileged attacker with CAP_NET_ADMIN in one namespace could reconfigure tunnels in other namespaces, potentially allowing unauthorized network manipulation and privilege escalation.
Technical details
The vulnerability is a privilege escalation flaw in the ipip6_changelink() function in net/ipv6/sit.c. The function operates across two network namespaces (the device's netns and the tunnel's netns) but only checks CAP_NET_ADMIN capability against the device's namespace, not the tunnel's namespace. An attacker with sufficient privileges in the device namespace but lacking privileges in the tunnel namespace could invoke changelink operations to reconfigure tunnels residing in the target namespace. The fix adds a call to rtnl_dev_link_net_capable() at the top of ipip6_changelink() to enforce proper capability checks before parsing any attributes. This bug affects all Linux kernel versions with the SIT cross-netns feature and was patched in 2026.
Affected products
- Linux Linux kernel All versions with SIT cross-netns support (from 5e6700b3bf98 onward)
Timeline
- 2026-08-15: disclosed
- 2026-06-21: patched: Patch merged upstream