net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
Published Aug 15, 2026
8.8
HIGHCVSS 3.1
EPSS 0.18%
Description
ip6gre_changelink() and ip6erspan_changelink() operate on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net.
Gate both ops on rtnl_dev_link_net_capable() at their top, before any attribute is parsed.
Affected products
-
- Version 4.19.100StatusaffectedConstraints<4.20
- Version 5.4.16StatusaffectedConstraints<5.5
- Version
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints-
- Version
-
- Version 5.5StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.5
- Version 5.10.261StatusunaffectedConstraints<=5.10.*
- Version 5.15.212StatusunaffectedConstraints<=5.15.*
- Version 6.1.178StatusunaffectedConstraints<=6.1.*
- Version 6.12.97StatusunaffectedConstraints<=6.12.*
- Version 6.18.40StatusunaffectedConstraints<=6.18.*
- Version 6.6.145StatusunaffectedConstraints<=6.6.*
- Version 7.1.5StatusunaffectedConstraints<=7.1.*
- Version 7.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
If IPv6 GRE or IP-ERSpan tunnels are not in use, their respective kernel modules (`ip6_gre` and `ip6erspan`) can be blacklisted to prevent exploitation. Create a file such as `/etc/modprobe.d/disable-ip6gre.conf` with the following content: ``` install ip6_gre /bin/true install ip6erspan /bin/true ``` After creating the file, regenerate the initramfs and reboot the system for the changes to take effect. This mitigation may impact network functionality if these tunnel types are actively used.
References (13)
- https://access.redhat.com/security/cve/CVE-2026-72052 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2516306 Issue Tracking
- https://git.kernel.org/stable/c/03d8843b143ebbbfaf48511922abc6e886575a61
- https://git.kernel.org/stable/c/0caa9f348f8b5356900de77b0bb89a697c4aff20
- https://git.kernel.org/stable/c/129f8939e5af683cec3a1a5edcb40a64636ad81e
- https://git.kernel.org/stable/c/1d4d8ee002083ca4ead5353662bf8362428af57f
- https://git.kernel.org/stable/c/220162c9fedbe992da70d70f50a10da4f45f914c
- https://git.kernel.org/stable/c/c38c8b0db3c65b597e7ece317b6cb59de3d15e69
- https://git.kernel.org/stable/c/e3724dedf57761c6de52f4d604ec74f66fd61611
- https://git.kernel.org/stable/c/f00a50876d2818bd6dc86fa98b3ef360884c53c8
- https://lore.kernel.org/linux-cve-announce/2026081515-CVE-2026-72052-1653@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-72052
- https://www.cve.org/CVERecord?id=CVE-2026-72052
Change history (0)
No recorded changes yet.