CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-63829

highCVSS 8.8covered by 2 sourcesfirst seen 2026-07-14
In the Linux kernel, the following vulnerability has been resolved: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink A tunnel changelink() operates on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net. Add rtnl_dev_link_net_capable() next to rtnl_get_net_ns_capable() in net/core/rtnetlink.c. It requires CAP_NET_ADMIN in the link netns and is skipped when the link netns is dev_net(dev), where the rtnl path already checked it. The other patches in this series use the same helper. Gate ipgre_changelink() and erspan_changelink() with it, at the top of the op before any attribute is parsed, because the parsers update live tunnel fields first. ipgre_netlink_parms() sets t->collect_md before ip_tunnel_changelink() runs. Commit 8b484efd5cb4 ("ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().") added the same check on the ioctl path. This adds it on RTM_NEWLINK.

CSIRTS triage

What
This vulnerability requires CAP_NET_ADMIN in the device netns for changelink operations.
Who is affected
Deployments using the net subsystem with changelink functionality.
Urgency
Remediation is advised to enhance security, with no current exploitation reported.
Action
Implement the CAP_NET_ADMIN requirement for changelink.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-63829

Get an email if CVE-2026-63829 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-63829

CVE.org record

Embed the live status

CVE-2026-63829 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-63829 status](https://www.csirts.com/badge/CVE-2026-63829)](https://www.csirts.com/cve/CVE-2026-63829)