Answer in brief
CVE-2026-68142 records a Unknown severity vulnerability in geneve: require CAP_NET_ADMIN in the device netns for changelink. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=5b861f6baa3a22a48d7a4ad0ce38a223d36c978a <2abdacc927c92fa6a9cc8341e8c9b88dcb561553 || >=5b861f6baa3a22a48d7a4ad0ce38a223d36c978a <9de5518fc1fab583526a8f66b8e505c4864dc60a || >=5b861f6baa3a22a48d7a4ad0ce38a223d36c978a <f8c498585d2a08aa623748353c3e61467b7e9fd2 || >=5b861f6baa3a22a48d7a4ad0ce38a223d36c978a <95f45e20f1b2cec13823f0f68060ab4b2261b2c1 || >=5b861f6baa3a22a48d7a4ad0ce38a223d36c978a <8efb8f8bbb353b8f2fdf4f37534c6d96c9f69e01 | 2abdacc927c92fa6a9cc8341e8c9b88dcb561553, 9de5518fc1fab583526a8f66b8e505c4864dc60a, f8c498585d2a08aa623748353c3e61467b7e9fd2, 95f45e20f1b2cec13823f0f68060ab4b2261b2c1, 8efb8f8bbb353b8f2fdf4f37534c6d96c9f69e01 |
| Linux/Linuxgeneric | 4.14 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: geneve: require CAP_NET_ADMIN in the device netns for changelink A tunnel changelink() operates on at most two netns, dev_net(dev) and the sticky underlay netns geneve->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in geneve->net can rewrite a geneve device whose underlay lives in geneve->net. geneve_changelink() applies the new configuration against geneve->net: geneve_link_config() and the geneve_quiesce()/geneve_unquiesce() pair reopen the underlay sockets in that netns (geneve_sock_add() uses geneve->net), so the same reasoning as the tunnel changelink series applies here. Gate geneve_changelink() with rtnl_dev_link_net_capable(), at the top of the op before any attribute is parsed, matching ipgre_changelink() and the rest of the "require CAP_NET_ADMIN in the device netns for changelink" series. Found by 0sec automated security-research tooling (https://0sec.ai).
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-68142 records a Unknown severity vulnerability in geneve: require CAP_NET_ADMIN in the device netns for changelink. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=5b861f6baa3a22a48d7a4ad0ce38a223d36c978a <2abdacc927c92fa6a9cc8341e8c9b88dcb561553 || >=5b861f6baa3a22a48d7a4ad0ce38a223d36c978a <9de5518fc1fab583526a8f66b8e505c4864dc60a || >=5b861f6baa3a22a48d7a4ad0ce38a223d36c978a <f8c498585d2a08aa623748353c3e61467b7e9fd2 || >=5b861f6baa3a22a48d7a4ad0ce38a223d36c978a <95f45e20f1b2cec13823f0f68060ab4b2261b2c1 || >=5b861f6baa3a22a48d7a4ad0ce38a223d36c978a <8efb8f8bbb353b8f2fdf4f37534c6d96c9f69e01 | 2abdacc927c92fa6a9cc8341e8c9b88dcb561553, 9de5518fc1fab583526a8f66b8e505c4864dc60a, f8c498585d2a08aa623748353c3e61467b7e9fd2, 95f45e20f1b2cec13823f0f68060ab4b2261b2c1, 8efb8f8bbb353b8f2fdf4f37534c6d96c9f69e01 |
| Linux/Linuxgeneric | 4.14 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: geneve: require CAP_NET_ADMIN in the device netns for changelink A tunnel changelink() operates on at most two netns, dev_net(dev) and the sticky underlay netns geneve->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in geneve->net can rewrite a geneve device whose underlay lives in geneve->net. geneve_changelink() applies the new configuration against geneve->net: geneve_link_config() and the geneve_quiesce()/geneve_unquiesce() pair reopen the underlay sockets in that netns (geneve_sock_add() uses geneve->net), so the same reasoning as the tunnel changelink series applies here. Gate geneve_changelink() with rtnl_dev_link_net_capable(), at the top of the op before any attribute is parsed, matching ipgre_changelink() and the rest of the "require CAP_NET_ADMIN in the device netns for changelink" series. Found by 0sec automated security-research tooling (https://0sec.ai).
Quoted source text, attributed separately from HOL analysis.