SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-72052

HIGH · CVSS 8.8 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of network namespaces, specifically in the ip6gre_changelink() and ip6erspan_changelink() functions, which fail to properly enforce CAP_NET_ADMIN permissions across different network namespaces. This oversight allows a privileged user in one namespace to manipulate tunnel links in another namespace, potentially leading to unauthorized network configurations and security breaches. System administrators and security teams managing Linux environments should prioritize addressing this vulnerability to safeguard against potential exploitation.

CVE
CVE-2026-72052
Severity
HIGH
CVSS
8.8
EPSS
0.17%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink ip6gre_changelink() and ip6erspan_changelink() operate on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net. Gate both ops on rtnl_dev_link_net_capable() at their top, before any attribute is parsed.