CVE-2026-68142

Source
https://cve.org/CVERecord?id=CVE-2026-68142
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68142.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68142
Downstream
Published
2026-08-10T11:59:06Z
Modified
2026-08-21T03:30:44Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
geneve: require CAP_NET_ADMIN in the device netns for changelink
Details

In the Linux kernel, the following vulnerability has been resolved:

geneve: require CAP_NET_ADMIN in the device netns for changelink

A tunnel changelink() operates on at most two netns, dev_net(dev) and the sticky underlay netns geneve->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in geneve->net can rewrite a geneve device whose underlay lives in geneve->net.

geneve_changelink() applies the new configuration against geneve->net: geneve_link_config() and the geneve_quiesce()/geneve_unquiesce() pair reopen the underlay sockets in that netns (geneve_sock_add() uses geneve->net), so the same reasoning as the tunnel changelink series applies here.

Gate geneve_changelink() with rtnl_dev_link_net_capable(), at the top of the op before any attribute is parsed, matching ipgre_changelink() and the rest of the "require CAP_NET_ADMIN in the device netns for changelink" series.

Found by 0sec automated security-research tooling (https://0sec.ai).

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68142.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5b861f6baa3a22a48d7a4ad0ce38a223d36c978a
Fixed
a5522963c57f12df5f9db804ebfc472b58eef0ae
Fixed
278c6a31ee27c931c722202c8c06cc3253923254
Fixed
11a7d989d00160481a273eb4f7f05f64b5a6ffdf
Fixed
2abdacc927c92fa6a9cc8341e8c9b88dcb561553
Fixed
9de5518fc1fab583526a8f66b8e505c4864dc60a
Fixed
f8c498585d2a08aa623748353c3e61467b7e9fd2
Fixed
95f45e20f1b2cec13823f0f68060ab4b2261b2c1
Fixed
8efb8f8bbb353b8f2fdf4f37534c6d96c9f69e01

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68142.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.14.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68142.json"