Answer in brief
CVE-2026-72052 records a Unknown severity vulnerability in net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-72052 records a Unknown severity vulnerability in net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=690afc165bb314354667f67157c1a1aea7dc797a <129f8939e5af683cec3a1a5edcb40a64636ad81e || >=690afc165bb314354667f67157c1a1aea7dc797a <e3724dedf57761c6de52f4d604ec74f66fd61611 || >=690afc165bb314354667f67157c1a1aea7dc797a <220162c9fedbe992da70d70f50a10da4f45f914c || >=690afc165bb314354667f67157c1a1aea7dc797a <1d4d8ee002083ca4ead5353662bf8362428af57f || >=690afc165bb314354667f67157c1a1aea7dc797a <0caa9f348f8b5356900de77b0bb89a697c4aff20 || >=690afc165bb314354667f67157c1a1aea7dc797a <03d8843b143ebbbfaf48511922abc6e886575a61 || >=690afc165bb314354667f67157c1a1aea7dc797a <c38c8b0db3c65b597e7ece317b6cb59de3d15e69 || >=690afc165bb314354667f67157c1a1aea7dc797a <f00a50876d2818bd6dc86fa98b3ef360884c53c8 || d0201d2405dac8d9b16773e97709925e397552d0 || 7943bb0f06365cf5e32f3cf8a6b29eeae981fb8a || >=4.19.100 <4.20 || >=5.4.16 <5.5 | 129f8939e5af683cec3a1a5edcb40a64636ad81e, e3724dedf57761c6de52f4d604ec74f66fd61611, 220162c9fedbe992da70d70f50a10da4f45f914c, 1d4d8ee002083ca4ead5353662bf8362428af57f, 0caa9f348f8b5356900de77b0bb89a697c4aff20, 03d8843b143ebbbfaf48511922abc6e886575a61, c38c8b0db3c65b597e7ece317b6cb59de3d15e69, f00a50876d2818bd6dc86fa98b3ef360884c53c8, 4.20, 5.5 |
| Linux/Linuxgeneric | 5.5 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink ip6gre_changelink() and ip6erspan_changelink() operate on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net. Gate both ops on rtnl_dev_link_net_capable() at their top, before any attribute is parsed.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=690afc165bb314354667f67157c1a1aea7dc797a <129f8939e5af683cec3a1a5edcb40a64636ad81e || >=690afc165bb314354667f67157c1a1aea7dc797a <e3724dedf57761c6de52f4d604ec74f66fd61611 || >=690afc165bb314354667f67157c1a1aea7dc797a <220162c9fedbe992da70d70f50a10da4f45f914c || >=690afc165bb314354667f67157c1a1aea7dc797a <1d4d8ee002083ca4ead5353662bf8362428af57f || >=690afc165bb314354667f67157c1a1aea7dc797a <0caa9f348f8b5356900de77b0bb89a697c4aff20 || >=690afc165bb314354667f67157c1a1aea7dc797a <03d8843b143ebbbfaf48511922abc6e886575a61 || >=690afc165bb314354667f67157c1a1aea7dc797a <c38c8b0db3c65b597e7ece317b6cb59de3d15e69 || >=690afc165bb314354667f67157c1a1aea7dc797a <f00a50876d2818bd6dc86fa98b3ef360884c53c8 || d0201d2405dac8d9b16773e97709925e397552d0 || 7943bb0f06365cf5e32f3cf8a6b29eeae981fb8a || >=4.19.100 <4.20 || >=5.4.16 <5.5 | 129f8939e5af683cec3a1a5edcb40a64636ad81e, e3724dedf57761c6de52f4d604ec74f66fd61611, 220162c9fedbe992da70d70f50a10da4f45f914c, 1d4d8ee002083ca4ead5353662bf8362428af57f, 0caa9f348f8b5356900de77b0bb89a697c4aff20, 03d8843b143ebbbfaf48511922abc6e886575a61, c38c8b0db3c65b597e7ece317b6cb59de3d15e69, f00a50876d2818bd6dc86fa98b3ef360884c53c8, 4.20, 5.5 |
| Linux/Linuxgeneric | 5.5 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink ip6gre_changelink() and ip6erspan_changelink() operate on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net. Gate both ops on rtnl_dev_link_net_capable() at their top, before any attribute is parsed.
Quoted source text, attributed separately from HOL analysis.