{"id":"CVE-2026-68142","summary":"geneve: require CAP_NET_ADMIN in the device netns for changelink","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ngeneve: require CAP_NET_ADMIN in the device netns for changelink\n\nA tunnel changelink() operates on at most two netns, dev_net(dev) and\nthe sticky underlay netns geneve-\u003enet. They differ once the device is\ncreated in or moved to a netns other than the one the request runs in.\nThe rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev),\nso a caller privileged there but not in geneve-\u003enet can rewrite a geneve\ndevice whose underlay lives in geneve-\u003enet.\n\ngeneve_changelink() applies the new configuration against geneve-\u003enet:\ngeneve_link_config() and the geneve_quiesce()/geneve_unquiesce() pair\nreopen the underlay sockets in that netns (geneve_sock_add() uses\ngeneve-\u003enet), so the same reasoning as the tunnel changelink series\napplies here.\n\nGate geneve_changelink() with rtnl_dev_link_net_capable(), at the top of\nthe op before any attribute is parsed, matching ipgre_changelink() and\nthe rest of the \"require CAP_NET_ADMIN in the device netns for\nchangelink\" series.\n\nFound by 0sec automated security-research tooling (https://0sec.ai).","modified":"2026-08-21T03:30:44.019212846Z","published":"2026-08-10T11:59:06.048Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68142.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/11a7d989d00160481a273eb4f7f05f64b5a6ffdf"},{"type":"WEB","url":"https://git.kernel.org/stable/c/278c6a31ee27c931c722202c8c06cc3253923254"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2abdacc927c92fa6a9cc8341e8c9b88dcb561553"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8efb8f8bbb353b8f2fdf4f37534c6d96c9f69e01"},{"type":"WEB","url":"https://git.kernel.org/stable/c/95f45e20f1b2cec13823f0f68060ab4b2261b2c1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9de5518fc1fab583526a8f66b8e505c4864dc60a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a5522963c57f12df5f9db804ebfc472b58eef0ae"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f8c498585d2a08aa623748353c3e61467b7e9fd2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68142.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68142"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"5b861f6baa3a22a48d7a4ad0ce38a223d36c978a"},{"fixed":"a5522963c57f12df5f9db804ebfc472b58eef0ae"},{"fixed":"278c6a31ee27c931c722202c8c06cc3253923254"},{"fixed":"11a7d989d00160481a273eb4f7f05f64b5a6ffdf"},{"fixed":"2abdacc927c92fa6a9cc8341e8c9b88dcb561553"},{"fixed":"9de5518fc1fab583526a8f66b8e505c4864dc60a"},{"fixed":"f8c498585d2a08aa623748353c3e61467b7e9fd2"},{"fixed":"95f45e20f1b2cec13823f0f68060ab4b2261b2c1"},{"fixed":"8efb8f8bbb353b8f2fdf4f37534c6d96c9f69e01"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68142.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.14.0"},{"fixed":"5.10.265"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.216"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.183"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.148"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.101"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.42"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68142.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}