All of lore.kernel.org
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-72052: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
Date: Sat, 15 Aug 2026 15:02:11 +0900	[thread overview]
Message-ID: <2026081515-CVE-2026-72052-1653@gregkh> (raw)

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink

ip6gre_changelink() and ip6erspan_changelink() operate on at most two
netns, dev_net(dev) and the tunnel link netns t->net. They differ once
the device is created in or moved to a netns other than the one the
request runs in. The rtnl changelink path checks CAP_NET_ADMIN only
against dev_net(dev), so a caller privileged there but not in t->net can
rewrite a tunnel that lives in t->net.

Gate both ops on rtnl_dev_link_net_capable() at their top, before any
attribute is parsed.

The Linux kernel CVE team has assigned CVE-2026-72052 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.5 with commit 690afc165bb314354667f67157c1a1aea7dc797a and fixed in 5.10.261 with commit 129f8939e5af683cec3a1a5edcb40a64636ad81e
	Issue introduced in 5.5 with commit 690afc165bb314354667f67157c1a1aea7dc797a and fixed in 5.15.212 with commit e3724dedf57761c6de52f4d604ec74f66fd61611
	Issue introduced in 5.5 with commit 690afc165bb314354667f67157c1a1aea7dc797a and fixed in 6.1.178 with commit 220162c9fedbe992da70d70f50a10da4f45f914c
	Issue introduced in 5.5 with commit 690afc165bb314354667f67157c1a1aea7dc797a and fixed in 6.6.145 with commit 1d4d8ee002083ca4ead5353662bf8362428af57f
	Issue introduced in 5.5 with commit 690afc165bb314354667f67157c1a1aea7dc797a and fixed in 6.12.97 with commit 0caa9f348f8b5356900de77b0bb89a697c4aff20
	Issue introduced in 5.5 with commit 690afc165bb314354667f67157c1a1aea7dc797a and fixed in 6.18.40 with commit 03d8843b143ebbbfaf48511922abc6e886575a61
	Issue introduced in 5.5 with commit 690afc165bb314354667f67157c1a1aea7dc797a and fixed in 7.1.5 with commit c38c8b0db3c65b597e7ece317b6cb59de3d15e69
	Issue introduced in 5.5 with commit 690afc165bb314354667f67157c1a1aea7dc797a and fixed in 7.2-rc1 with commit f00a50876d2818bd6dc86fa98b3ef360884c53c8
	Issue introduced in 4.19.100 with commit d0201d2405dac8d9b16773e97709925e397552d0
	Issue introduced in 5.4.16 with commit 7943bb0f06365cf5e32f3cf8a6b29eeae981fb8a

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-72052
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	net/ipv6/ip6_gre.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/129f8939e5af683cec3a1a5edcb40a64636ad81e
	https://git.kernel.org/stable/c/e3724dedf57761c6de52f4d604ec74f66fd61611
	https://git.kernel.org/stable/c/220162c9fedbe992da70d70f50a10da4f45f914c
	https://git.kernel.org/stable/c/1d4d8ee002083ca4ead5353662bf8362428af57f
	https://git.kernel.org/stable/c/0caa9f348f8b5356900de77b0bb89a697c4aff20
	https://git.kernel.org/stable/c/03d8843b143ebbbfaf48511922abc6e886575a61
	https://git.kernel.org/stable/c/c38c8b0db3c65b597e7ece317b6cb59de3d15e69
	https://git.kernel.org/stable/c/f00a50876d2818bd6dc86fa98b3ef360884c53c8

                 reply	other threads:[~2026-08-15  6:08 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2026081515-CVE-2026-72052-1653@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=cve@kernel.org \
    --cc=gregkh@kernel.org \
    --cc=linux-cve-announce@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.