SB20260816478 - Improper access control in Linux kernel ipv6



SB20260816478 - Improper access control in Linux kernel ipv6

Published: August 16, 2026

Security Bulletin ID SB20260816478
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2026-72052)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify tunnel link configuration across network namespaces.

The vulnerability exists due to improper access control in ip6gre_changelink() and ip6erspan_changelink() when handling changelink requests for devices and tunnel links in different network namespaces. A remote privileged user can send a crafted changelink request to modify tunnel link configuration across network namespaces.

The issue occurs when the device network namespace differs from the tunnel link network namespace, causing capability checks to be applied only to the device namespace.


Remediation

Install update from vendor's website.