๐Ÿ” CVE Alert

CVE-2026-63917

UNKNOWN 0.0

ip6: vti: Use ip6_tnl.net in vti6_changelink().

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_changelink(). ip netns add ns1 ip netns add ns2 ip -n ns1 link add vti6_test type vti6 remote ::1 local ::2 key 7 ip -n ns1 link set vti6_test netns ns2 ip -n ns2 link set vti6_test type vti6 remote ::3 local ::4 key 9 ip netns del ns2 ip netns del ns1 [ 132.495484] ------------[ cut here ]------------ [ 132.497609] kernel BUG at net/core/dev.c:12376! Commit 61220ab34948 ("vti6: Enable namespace changing") dropped NETIF_F_NETNS_LOCAL from vti6 devices. A vti6 tunnel can then move through IFLA_NET_NS_FD. After the move dev_net(dev) points at the new netns while t->net stays at the creation netns. vti6_changelink() and vti6_update() still use dev_net(dev) and dev_net(t->dev). They unlink from one per netns hash and relink into another. The creation netns is left with a stale entry. cleanup_net() of that netns later walks freed memory. Reachable from an unprivileged user namespace (unshare --user --map-root-user --net). Cross tenant scope on container hosts.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
61220ab349485d911083d0b7990ccd3db6c63297 < 0cdce7618464f7fb06f461e8f4ad575cb1d570f4 61220ab349485d911083d0b7990ccd3db6c63297 < f5c68875e25f331e497ddfbe81e2d8163a87f136 61220ab349485d911083d0b7990ccd3db6c63297 < d9c5eecdb3c740e65038651db7c686b10d76d1bc 61220ab349485d911083d0b7990ccd3db6c63297 < f1e89a943ee574d0f2f16246eb3f2d7330fdeb03 61220ab349485d911083d0b7990ccd3db6c63297 < 225b467e3b631f38be22e4b38062a1fed02fdd21 61220ab349485d911083d0b7990ccd3db6c63297 < fc32be9ac2788524c6b24efd681cce7a6e731a92 61220ab349485d911083d0b7990ccd3db6c63297 < ee1778ba0f5cb53be771f97017d01eb356c797bf 61220ab349485d911083d0b7990ccd3db6c63297 < 11b326fb0a374f4654f9be22d0f0f7abd9f7d3fe
Linux / Linux
3.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/0cdce7618464f7fb06f461e8f4ad575cb1d570f4 git.kernel.org: https://git.kernel.org/stable/c/f5c68875e25f331e497ddfbe81e2d8163a87f136 git.kernel.org: https://git.kernel.org/stable/c/d9c5eecdb3c740e65038651db7c686b10d76d1bc git.kernel.org: https://git.kernel.org/stable/c/f1e89a943ee574d0f2f16246eb3f2d7330fdeb03 git.kernel.org: https://git.kernel.org/stable/c/225b467e3b631f38be22e4b38062a1fed02fdd21 git.kernel.org: https://git.kernel.org/stable/c/fc32be9ac2788524c6b24efd681cce7a6e731a92 git.kernel.org: https://git.kernel.org/stable/c/ee1778ba0f5cb53be771f97017d01eb356c797bf git.kernel.org: https://git.kernel.org/stable/c/11b326fb0a374f4654f9be22d0f0f7abd9f7d3fe