CVE-2026-68432
Linux kernel VXLAN changelink flaw lets privileged netns users alter devices across netns.
Is CVE-2026-68432 being exploited?
Not confirmed. CVE-2026-68432 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.13% probability of exploitation in the next 30 days.
How severe is CVE-2026-68432?
CVE-2026-68432 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-68432?
Yes. A fix has been recorded for CVE-2026-68432. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-68432 affect?
CVE-2026-68432 affects Linux kernel (vxlan driver). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-68432?
Install kernel patch, restrict CAP_NET_ADMIN, audit netns privileges
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
A caller with CAP_NET_ADMIN in one netns can modify a VXLAN device in another netns, reopen underlay sockets, enabling privilege escalation and cross-netns network compromise.
Patch when possible
- affected>= 8bcdc4f3a20be949df54b67e5ae2734daabb5792 and < b95a8743e58f7efed5ddc4cb73829b66f17feab0
- affected>= 8bcdc4f3a20be949df54b67e5ae2734daabb5792 and < 7465ade989ba84adc2bfa58bad3ca25d249f0f7a
- affected>= 8bcdc4f3a20be949df54b67e5ae2734daabb5792 and < 0aa580a8bbbed2507b4582a1f0ef581d480d06ed
- affected>= 8bcdc4f3a20be949df54b67e5ae2734daabb5792 and < b3793d7dccb192ffff29894d11824db6251acdd5
- affected>= 8bcdc4f3a20be949df54b67e5ae2734daabb5792 and < 32d10c46bfde3e9b274e9e1bd6399d0ebea8f60f
- affected>= 8bcdc4f3a20be949df54b67e5ae2734daabb5792 and < 730c7e5fea7f06e0cdf21c547222ec93234fd1d6
- affected>= 8bcdc4f3a20be949df54b67e5ae2734daabb5792 and < e8ad0d311e225939a9a6c745d6cc384c7364ec87
- affected>= 8bcdc4f3a20be949df54b67e5ae2734daabb5792 and < 3a61bd9637f3d929aa846e4eb3d98b48c26fcb0e
- affected4.11
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.