SB20260816479 - Improper access control in Linux kernel ipv4
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-72053)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to modify IPIP tunnel configuration in another network namespace.
The vulnerability exists due to improper access control in ipip_changelink() in net/ipv4/ipip.c when handling changelink requests for an IPIP device whose tunnel link resides in a different network namespace. A local privileged user can send a changelink request from a network namespace where they have CAP_NET_ADMIN to modify IPIP tunnel configuration in another network namespace.
The issue occurs when dev_net(dev) and the tunnel link namespace differ, such as after the device is created in or moved to a different network namespace.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/26544021d5c49cc6ae8a968ccb5033e6363854a4
- https://git.kernel.org/stable/c/68cadc3698c7de88966d306d12ec9c6217da228a
- https://git.kernel.org/stable/c/8211a26324667980a463c069469a818e71207e02
- https://git.kernel.org/stable/c/91571643e554ae89a91942380d5f5361fb7060a2
- https://git.kernel.org/stable/c/983cc4aa7e6f633b34c3ee743771252d7afa9a90
- https://git.kernel.org/stable/c/d49edcc65e0a37cc9b386a94415c5d6670ca8b71