SB2026081287 - Improper access control in Linux kernel net vxlan driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-68432)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to modify VXLAN device configuration across network namespaces.
The vulnerability exists due to improper access control in vxlan_changelink() when handling changelink requests for a VXLAN device whose underlay network namespace differs from the device network namespace. A local privileged user can send a crafted changelink request to modify VXLAN device configuration across network namespaces.
The issue occurs when the caller has CAP_NET_ADMIN in the device network namespace but not in the VXLAN underlay network namespace.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/32d10c46bfde3e9b274e9e1bd6399d0ebea8f60f
- https://git.kernel.org/stable/c/3a61bd9637f3d929aa846e4eb3d98b48c26fcb0e
- https://git.kernel.org/stable/c/730c7e5fea7f06e0cdf21c547222ec93234fd1d6
- https://git.kernel.org/stable/c/b3793d7dccb192ffff29894d11824db6251acdd5
- https://git.kernel.org/stable/c/e8ad0d311e225939a9a6c745d6cc384c7364ec87