CVE-2026-72053: Linux

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net: ipip: require CAP_NET_ADMIN in the device netns for changelink ipip_changelink() operates on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net. Gate ipip_changelink() on rtnl_dev_link_net_capable() at its top, before any attribute is parsed.

Affected products

  • Linux Linux: from 3.12, before 5.10.266 (fixed in 5.10.266); from 5.11, before 5.15.217 (fixed in 5.15.217); from 5.16, before 6.1.178 (fixed in 6.1.178); from 6.2, before 6.6.145 (fixed in 6.6.145); from 6.7, before 6.12.97 (fixed in 6.12.97); from 6.13, before 6.18.40 (fixed in 6.18.40); …

Published 2026-08-15. Last modified 2026-08-23.