From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C54FD348C6D for ; Sat, 15 Aug 2026 06:08:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786774138; cv=none; b=iLbR01VE+e/PunslchyiiHS6VNJZH1dH43C4cJw9GAqGUwzWAKI0uurg3RGwkFQQxrkh0XQWP07iBsXT7LMghcm8huKt+7faNtJ+SmFMNwxBFGSiUPyAK5hE3XyXajIRlrRVo8R9XCizpztiq0nLabNR4xeLyEv7zKxy7h/Ka7c= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786774138; c=relaxed/simple; bh=EQAK0UX5iYyK+Zw/cqDHRbVWtS2ZjtxcjMDA747EeWA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=HjooeCVdtwrXj7NEOvl3YA/Bfe9+GAI0SdMmfNn1f8oxR0jETFBCbWfgXizoGR+muFU1oLLgk0wJg0hvJ5+huWBSCJPHQKXd9v5mLSk+cFcjAO6Waxi/pVsZSmK7y/Utsg9c9itJ+1jCFw88fCX4lu8Wu77QozQn8HZW9W6pT28= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=SVMrfB4z; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="SVMrfB4z" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 292D71F000E9; Sat, 15 Aug 2026 06:08:56 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1786774137; bh=yHsGzQn1n9VVEc5oicJOn4EnD20ei2VYKgF+OjeQ3q0=; h=From:To:Cc:Subject:Date:Reply-To; b=SVMrfB4z7+SbzsE3KhhDGfOCB5v2Tg9I3GxUj9EJiQW7JSmo1A64ckuXFs4ueIGR6 02rwMaC03wbiSJpg05b+2PT1J4EI+qlXqMhSJ1A2XRqPUbt7/DMPbtF/XztnFI0fUS SGhrD90b1XshCIXr+RiqpoIHgDhePwrnjE2fEAWU= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-72052: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink Date: Sat, 15 Aug 2026 15:02:11 +0900 Message-ID: <2026081515-CVE-2026-72052-1653@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3796; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=+5xpgxWPJP+4Sy867C/FdVhMUf5+Qzrst3ui3e0z8tg=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkNDKvjnbbKuHq4113s7Xj7QND6cGmhSKwR98OwWqkb6 iF1V2d0xLIwCDIxyIopsnzZxnN0f8UhRS9D29Mwc1iZQIYwcHEKwESKeBgW7HI8OpF9wo7d/+1+ 5/4N+ONlaqZYyzDPeqXyF063vfl3xG7ZWh6pDJc6kaADAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink ip6gre_changelink() and ip6erspan_changelink() operate on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net. Gate both ops on rtnl_dev_link_net_capable() at their top, before any attribute is parsed. The Linux kernel CVE team has assigned CVE-2026-72052 to this issue. Affected and fixed versions =========================== Issue introduced in 5.5 with commit 690afc165bb314354667f67157c1a1aea7dc797a and fixed in 5.10.261 with commit 129f8939e5af683cec3a1a5edcb40a64636ad81e Issue introduced in 5.5 with commit 690afc165bb314354667f67157c1a1aea7dc797a and fixed in 5.15.212 with commit e3724dedf57761c6de52f4d604ec74f66fd61611 Issue introduced in 5.5 with commit 690afc165bb314354667f67157c1a1aea7dc797a and fixed in 6.1.178 with commit 220162c9fedbe992da70d70f50a10da4f45f914c Issue introduced in 5.5 with commit 690afc165bb314354667f67157c1a1aea7dc797a and fixed in 6.6.145 with commit 1d4d8ee002083ca4ead5353662bf8362428af57f Issue introduced in 5.5 with commit 690afc165bb314354667f67157c1a1aea7dc797a and fixed in 6.12.97 with commit 0caa9f348f8b5356900de77b0bb89a697c4aff20 Issue introduced in 5.5 with commit 690afc165bb314354667f67157c1a1aea7dc797a and fixed in 6.18.40 with commit 03d8843b143ebbbfaf48511922abc6e886575a61 Issue introduced in 5.5 with commit 690afc165bb314354667f67157c1a1aea7dc797a and fixed in 7.1.5 with commit c38c8b0db3c65b597e7ece317b6cb59de3d15e69 Issue introduced in 5.5 with commit 690afc165bb314354667f67157c1a1aea7dc797a and fixed in 7.2-rc1 with commit f00a50876d2818bd6dc86fa98b3ef360884c53c8 Issue introduced in 4.19.100 with commit d0201d2405dac8d9b16773e97709925e397552d0 Issue introduced in 5.4.16 with commit 7943bb0f06365cf5e32f3cf8a6b29eeae981fb8a Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-72052 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/ipv6/ip6_gre.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/129f8939e5af683cec3a1a5edcb40a64636ad81e https://git.kernel.org/stable/c/e3724dedf57761c6de52f4d604ec74f66fd61611 https://git.kernel.org/stable/c/220162c9fedbe992da70d70f50a10da4f45f914c https://git.kernel.org/stable/c/1d4d8ee002083ca4ead5353662bf8362428af57f https://git.kernel.org/stable/c/0caa9f348f8b5356900de77b0bb89a697c4aff20 https://git.kernel.org/stable/c/03d8843b143ebbbfaf48511922abc6e886575a61 https://git.kernel.org/stable/c/c38c8b0db3c65b597e7ece317b6cb59de3d15e69 https://git.kernel.org/stable/c/f00a50876d2818bd6dc86fa98b3ef360884c53c8