Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-63917

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
20/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ip6: vti: Use ip6_tnl.net in vti6_changelink().<br /> <br /> ip netns add ns1<br /> ip netns add ns2<br /> ip -n ns1 link add vti6_test type vti6 remote ::1 local ::2 key 7<br /> ip -n ns1 link set vti6_test netns ns2<br /> ip -n ns2 link set vti6_test type vti6 remote ::3 local ::4 key 9<br /> ip netns del ns2<br /> ip netns del ns1<br /> [ 132.495484] ------------[ cut here ]------------<br /> [ 132.497609] kernel BUG at net/core/dev.c:12376!<br /> <br /> Commit 61220ab34948 ("vti6: Enable namespace changing") dropped<br /> NETIF_F_NETNS_LOCAL from vti6 devices. A vti6 tunnel can then<br /> move through IFLA_NET_NS_FD. After the move dev_net(dev) points<br /> at the new netns while t-&gt;net stays at the creation netns.<br /> <br /> vti6_changelink() and vti6_update() still use dev_net(dev) and<br /> dev_net(t-&gt;dev). They unlink from one per netns hash and relink<br /> into another. The creation netns is left with a stale entry.<br /> cleanup_net() of that netns later walks freed memory.<br /> <br /> Reachable from an unprivileged user namespace (unshare --user<br /> --map-root-user --net). Cross tenant scope on container hosts.