CVE-2026-63921
Received Received - Intake

Heap-based Buffer Overflow in Linux Kernel VTI Tunnel

Vulnerability report for CVE-2026-63921, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-19

Last updated on: 2026-07-19

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). After patch 1/2 in this series, vti6_update() unlinks and relinks the tunnel through t->net. vti6_siocdevprivate() still uses dev_net(dev) for the collision lookup. For a tunnel moved through IFLA_NET_NS_FD, dev_net(dev) is the new netns, not t->net. SIOCCHGTUNNEL on a migrated tunnel then runs: net = dev_net(dev) /* migrated netns */ t = vti6_locate(net, &p1, false) /* misses target in t->net */ ... t = netdev_priv(dev) vti6_update(t, &p1, false) /* mutates t->net's hash */ A caller in the migrated netns picks params that match a tunnel in the creation netns. The lookup in dev_net(dev) finds nothing. vti6_update() prepends the migrated tunnel at the head of the creation netns hash bucket for those params. Later lookups in the creation netns resolve to the migrated device. xfrm receive delivers the matched packets through a device the caller controls. Reachable from an unprivileged user namespace (unshare --user --map-root-user --net). Cross tenant scope on container hosts. Switch the SIOCCHGTUNNEL path on a non fallback device to use t->net for the lookup. The lookup now matches the netns vti6_update() operates on. Also add ns_capable(self->net->user_ns, CAP_NET_ADMIN) before the lookup. The check at the top of the case is against dev_net(dev)->user_ns, which after migration is the attacker's netns. A caller there can pick params absent from self->net, the lookup returns NULL, t becomes self, and vti6_update() inserts the device into the creation netns hash. The new check requires CAP_NET_ADMIN in the creation netns user_ns too. SIOCADDTUNNEL and SIOCCHGTUNNEL on the fallback device keep dev_net(dev), which equals init_net there.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-19
Last Modified
2026-07-19
Generated
2026-07-20
AI Q&A
2026-07-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a network tunnel management issue where a tunnel device moved to a different network namespace can be manipulated by an attacker in the new namespace. The attacker can cause the tunnel to be incorrectly linked in the original namespace's hash table, leading to packet delivery through a device they control. This is possible from an unprivileged user namespace.

Detection Guidance

This vulnerability is specific to the Linux kernel's IP6 VTI (Virtual Tunnel Interface) implementation. Detection requires checking kernel versions and examining tunnel configurations for potential misconfigurations or unauthorized modifications. No direct commands are provided in the context to detect this issue.

Impact Analysis

If exploited, this vulnerability could allow an attacker to intercept or manipulate network traffic by redirecting it through a tunnel they control. This could lead to data breaches, unauthorized access, or denial of service. It is particularly dangerous on container hosts where multiple tenants share resources.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR (data protection) or HIPAA (health information privacy). Organizations must ensure proper network isolation and access controls to mitigate risks.

Mitigation Strategies

Apply the Linux kernel patch that resolves this vulnerability. Ensure the patch addresses the issue with vti6_siocdevprivate() using ip6_tnl.net instead of dev_net(dev) for tunnel lookups. Update to a patched kernel version immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63921. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart