vxlan: require CAP_NET_ADMIN in the device netns for changelink
Summary
| CVE | CVE-2026-68432 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-12 00:17:43 UTC |
| Updated | 2026-08-12 00:17:43 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
vxlan: require CAP_NET_ADMIN in the device netns for changelink
A tunnel changelink() operates on at most two netns, dev_net(dev) and
the sticky underlay netns vxlan->net. They differ once the device is
created in or moved to a netns other than the one the request runs in.
The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),
so a caller privileged there but not in vxlan->net can rewrite a vxlan
device whose underlay lives in vxlan->net.
vxlan_changelink() validates and applies the new configuration against
vxlan->net (vxlan_config_validate(vxlan->net, ...)) and can reopen the
underlay socket in that netns, so the same reasoning as the tunnel
changelink series applies here.
Gate vxlan_changelink() with rtnl_dev_link_net_capable(), at the top of
the op before any attribute is parsed, matching ipgre_changelink() and
the rest of the "require CAP_NET_ADMIN in the device netns for
changelink" series.
Found by 0sec automated security-research tooling (https://0sec.ai). |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 8bcdc4f3a20be949df54b67e5ae2734daabb5792 b3793d7dccb192ffff29894d11824db6251acdd5 git |
Not specified |
| CNA |
Linux |
Linux |
affected 8bcdc4f3a20be949df54b67e5ae2734daabb5792 32d10c46bfde3e9b274e9e1bd6399d0ebea8f60f git |
Not specified |
| CNA |
Linux |
Linux |
affected 8bcdc4f3a20be949df54b67e5ae2734daabb5792 730c7e5fea7f06e0cdf21c547222ec93234fd1d6 git |
Not specified |
| CNA |
Linux |
Linux |
affected 8bcdc4f3a20be949df54b67e5ae2734daabb5792 e8ad0d311e225939a9a6c745d6cc384c7364ec87 git |
Not specified |
| CNA |
Linux |
Linux |
affected 8bcdc4f3a20be949df54b67e5ae2734daabb5792 3a61bd9637f3d929aa846e4eb3d98b48c26fcb0e git |
Not specified |
| CNA |
Linux |
Linux |
affected 4.11 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 4.11 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.148 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.101 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.42 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.6 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc5 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/32d10c46bfde3e9b274e9e1bd6399d0ebea8f60f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/e8ad0d311e225939a9a6c745d6cc384c7364ec87 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/b3793d7dccb192ffff29894d11824db6251acdd5 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/730c7e5fea7f06e0cdf21c547222ec93234fd1d6 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/3a61bd9637f3d929aa846e4eb3d98b48c26fcb0e |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.