๐Ÿ” CVE Alert

CVE-2026-74283

UNKNOWN 0.0

tipc: require net admin for TIPCv2 netlink mutators

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: tipc: require net admin for TIPCv2 netlink mutators TIPCv2 registers mutating generic-netlink operations without admin permission flags. Generic netlink only checks CAP_NET_ADMIN when an operation sets GENL_ADMIN_PERM or GENL_UNS_ADMIN_PERM, so a local unprivileged process can currently change TIPC state through commands such as TIPC_NL_NET_SET, TIPC_NL_KEY_SET, TIPC_NL_KEY_FLUSH, and bearer enable/disable. The legacy TIPC netlink API already checks netlink_net_capable(..., CAP_NET_ADMIN) for administrative commands. Give the TIPCv2 mutators the equivalent generic-netlink gate. Use GENL_UNS_ADMIN_PERM, which maps to the same namespace-aware CAP_NET_ADMIN check that netlink_net_capable() performs, so the behaviour matches the legacy path and keeps working for CAP_NET_ADMIN holders in a non-initial user namespace (containers). A QEMU/KASAN repro run as uid/gid 65534 with zero effective capabilities previously succeeded in changing the network id and node identity, setting and flushing key material, and enabling/disabling a UDP bearer. With this patch applied the same operations fail with -EPERM.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
0655f6a8635b1b66f2434d5556b1044c14b1ccaf < b06fb5f78a9af0929aaa47c92d0b7bca0617fb25 0655f6a8635b1b66f2434d5556b1044c14b1ccaf < 52864c6c13dcc292481eabfeb3c31a86c3ec06f2 0655f6a8635b1b66f2434d5556b1044c14b1ccaf < e87dcc1a644d087de0bb6c94c6dd28c29b89597f 0655f6a8635b1b66f2434d5556b1044c14b1ccaf < 9b937de4b3ded62a24da6e8d9d623cdb2748fa74 0655f6a8635b1b66f2434d5556b1044c14b1ccaf < c9668a4adb2264625daeeabc7466b783badd4614 0655f6a8635b1b66f2434d5556b1044c14b1ccaf < cebaefe1aceb650d5c99a4c0e1a4dde09e211818 0655f6a8635b1b66f2434d5556b1044c14b1ccaf < 56f0a2e0a1d004e025cd031c3a801ab73959269f 0655f6a8635b1b66f2434d5556b1044c14b1ccaf < 86b0c540e2ea397cde021eecd24145f7c16a3d4e
Linux / Linux
3.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/b06fb5f78a9af0929aaa47c92d0b7bca0617fb25 git.kernel.org: https://git.kernel.org/stable/c/52864c6c13dcc292481eabfeb3c31a86c3ec06f2 git.kernel.org: https://git.kernel.org/stable/c/e87dcc1a644d087de0bb6c94c6dd28c29b89597f git.kernel.org: https://git.kernel.org/stable/c/9b937de4b3ded62a24da6e8d9d623cdb2748fa74 git.kernel.org: https://git.kernel.org/stable/c/c9668a4adb2264625daeeabc7466b783badd4614 git.kernel.org: https://git.kernel.org/stable/c/cebaefe1aceb650d5c99a4c0e1a4dde09e211818 git.kernel.org: https://git.kernel.org/stable/c/56f0a2e0a1d004e025cd031c3a801ab73959269f git.kernel.org: https://git.kernel.org/stable/c/86b0c540e2ea397cde021eecd24145f7c16a3d4e