CVE-2026-63921

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
27/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().<br /> <br /> After patch 1/2 in this series, vti6_update() unlinks and relinks<br /> the tunnel through t-&gt;net. vti6_siocdevprivate() still uses<br /> dev_net(dev) for the collision lookup. For a tunnel moved through<br /> IFLA_NET_NS_FD, dev_net(dev) is the new netns, not t-&gt;net.<br /> <br /> SIOCCHGTUNNEL on a migrated tunnel then runs:<br /> <br /> net = dev_net(dev) /* migrated netns */<br /> t = vti6_locate(net, &amp;p1, false) /* misses target in t-&gt;net */<br /> ...<br /> t = netdev_priv(dev)<br /> vti6_update(t, &amp;p1, false) /* mutates t-&gt;net&amp;#39;s hash */<br /> <br /> A caller in the migrated netns picks params that match a tunnel<br /> in the creation netns. The lookup in dev_net(dev) finds nothing.<br /> vti6_update() prepends the migrated tunnel at the head of the<br /> creation netns hash bucket for those params. Later lookups in<br /> the creation netns resolve to the migrated device. xfrm receive<br /> delivers the matched packets through a device the caller controls.<br /> <br /> Reachable from an unprivileged user namespace (unshare --user<br /> --map-root-user --net). Cross tenant scope on container hosts.<br /> <br /> Switch the SIOCCHGTUNNEL path on a non fallback device to use<br /> t-&gt;net for the lookup. The lookup now matches the netns<br /> vti6_update() operates on.<br /> <br /> Also add ns_capable(self-&gt;net-&gt;user_ns, CAP_NET_ADMIN) before<br /> the lookup. The check at the top of the case is against<br /> dev_net(dev)-&gt;user_ns, which after migration is the attacker&amp;#39;s<br /> netns. A caller there can pick params absent from self-&gt;net,<br /> the lookup returns NULL, t becomes self, and vti6_update()<br /> inserts the device into the creation netns hash. The new check<br /> requires CAP_NET_ADMIN in the creation netns user_ns too.<br /> <br /> SIOCADDTUNNEL and SIOCCHGTUNNEL on the fallback device keep<br /> dev_net(dev), which equals init_net there.