SB20260816471 - Improper access control in Linux kernel ipv6
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-72061)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to modify tunnel configuration across network namespaces.
The vulnerability exists due to improper access control in ipip6_changelink() in the sit tunnel handler when handling changelink requests for a tunnel whose link network namespace differs from the device network namespace. A local privileged user can send a changelink request to modify tunnel configuration across network namespaces.
The issue occurs when the caller has CAP_NET_ADMIN in the device network namespace but not in the tunnel link network namespace.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/27ccb68e7cccead5d8c611665a45d23032d468b3
- https://git.kernel.org/stable/c/3118e97dae533fb45964b87bbed1801afcff7c65
- https://git.kernel.org/stable/c/388ccffbd2e7e5e4271f291085a7451865705305
- https://git.kernel.org/stable/c/7d139dec96691cde96cb40ed293e2d13d994fb4f
- https://git.kernel.org/stable/c/99ae3248b33df94201915d9c32e7470cdf08cfcd
- https://git.kernel.org/stable/c/c0ea1aedb37bb979e864ed7787975434bbd9db73
- https://git.kernel.org/stable/c/c5a0ae895432596b2f464172da8218e2d84e2932
- https://git.kernel.org/stable/c/cb41b308e9d867725d965b291dd085028e36a480