Improper access control in Linux kernel - CVE-2026-52909
Published: June 23, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to move a fallback tunnel device to another network namespace.
The vulnerability exists due to improper access control in the ip6_vti fallback tunnel device initialization when initializing the per-network-namespace fallback device. A local user can move the ip6_vti0 device to another network namespace to move a fallback tunnel device to another network namespace.
The issue affects the per-netns fallback tunnel device ip6_vti0.