Answer in brief
CVE-2026-72051 records a Unknown severity vulnerability in net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0bd8762824e73a3cce7b7560a97463301764b616 <2636d061bc237a2446a146e42dcc6563acfa7432 || >=0bd8762824e73a3cce7b7560a97463301764b616 <7f68f7928484f463a5bc0d50e6fdd8d16f55a5aa || >=0bd8762824e73a3cce7b7560a97463301764b616 <234cd54fc500f69db43e37de38603da617fbbeea || >=0bd8762824e73a3cce7b7560a97463301764b616 <d4bcc202a3530c856e1cb183384bc9cc8fddab22 || >=0bd8762824e73a3cce7b7560a97463301764b616 <2496fa0b7d180b3ad356b514e7ff93bb14e6140a | 2636d061bc237a2446a146e42dcc6563acfa7432, 7f68f7928484f463a5bc0d50e6fdd8d16f55a5aa, 234cd54fc500f69db43e37de38603da617fbbeea, d4bcc202a3530c856e1cb183384bc9cc8fddab22, 2496fa0b7d180b3ad356b514e7ff93bb14e6140a |
| Linux/Linuxgeneric | 3.12 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink ip6_tnl_changelink() operates on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net. Gate ip6_tnl_changelink() on rtnl_dev_link_net_capable() at its top, before any attribute is parsed.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-72051 records a Unknown severity vulnerability in net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0bd8762824e73a3cce7b7560a97463301764b616 <2636d061bc237a2446a146e42dcc6563acfa7432 || >=0bd8762824e73a3cce7b7560a97463301764b616 <7f68f7928484f463a5bc0d50e6fdd8d16f55a5aa || >=0bd8762824e73a3cce7b7560a97463301764b616 <234cd54fc500f69db43e37de38603da617fbbeea || >=0bd8762824e73a3cce7b7560a97463301764b616 <d4bcc202a3530c856e1cb183384bc9cc8fddab22 || >=0bd8762824e73a3cce7b7560a97463301764b616 <2496fa0b7d180b3ad356b514e7ff93bb14e6140a | 2636d061bc237a2446a146e42dcc6563acfa7432, 7f68f7928484f463a5bc0d50e6fdd8d16f55a5aa, 234cd54fc500f69db43e37de38603da617fbbeea, d4bcc202a3530c856e1cb183384bc9cc8fddab22, 2496fa0b7d180b3ad356b514e7ff93bb14e6140a |
| Linux/Linuxgeneric | 3.12 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink ip6_tnl_changelink() operates on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net. Gate ip6_tnl_changelink() on rtnl_dev_link_net_capable() at its top, before any attribute is parsed.
Quoted source text, attributed separately from HOL analysis.