Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-68142

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
10/08/2026
Última modificación:
19/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> geneve: require CAP_NET_ADMIN in the device netns for changelink<br /> <br /> A tunnel changelink() operates on at most two netns, dev_net(dev) and<br /> the sticky underlay netns geneve-&gt;net. They differ once the device is<br /> created in or moved to a netns other than the one the request runs in.<br /> The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),<br /> so a caller privileged there but not in geneve-&gt;net can rewrite a geneve<br /> device whose underlay lives in geneve-&gt;net.<br /> <br /> geneve_changelink() applies the new configuration against geneve-&gt;net:<br /> geneve_link_config() and the geneve_quiesce()/geneve_unquiesce() pair<br /> reopen the underlay sockets in that netns (geneve_sock_add() uses<br /> geneve-&gt;net), so the same reasoning as the tunnel changelink series<br /> applies here.<br /> <br /> Gate geneve_changelink() with rtnl_dev_link_net_capable(), at the top of<br /> the op before any attribute is parsed, matching ipgre_changelink() and<br /> the rest of the "require CAP_NET_ADMIN in the device netns for<br /> changelink" series.<br /> <br /> Found by 0sec automated security-research tooling (https://0sec.ai).