CVE-2026-72052
Linux kernel ip6_gre changelink allows netns privilege bypass and tunnel rewrite.
Is CVE-2026-72052 being exploited?
Not confirmed. CVE-2026-72052 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.17% probability of exploitation in the next 30 days.
How severe is CVE-2026-72052?
CVE-2026-72052 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72052?
Yes. A fix has been recorded for CVE-2026-72052. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72052 affect?
CVE-2026-72052 affects Linux kernel (ip6_gre), Linux kernel (ip6erspan), Linux distributions with vulnerable kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72052?
Apply vendor kernel updates or upstream patch; restrict CAP_NET_ADMIN privileges.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
A caller with CAP_NET_ADMIN in one network namespace can rewrite GRE/ERSPAN tunnels in another namespace, enabling traffic interception or local privilege escalation.
Patch when possible
- affected>= 690afc165bb314354667f67157c1a1aea7dc797a and < 129f8939e5af683cec3a1a5edcb40a64636ad81e
- affected>= 690afc165bb314354667f67157c1a1aea7dc797a and < e3724dedf57761c6de52f4d604ec74f66fd61611
- affected>= 690afc165bb314354667f67157c1a1aea7dc797a and < 220162c9fedbe992da70d70f50a10da4f45f914c
- affected>= 690afc165bb314354667f67157c1a1aea7dc797a and < 1d4d8ee002083ca4ead5353662bf8362428af57f
- affected>= 690afc165bb314354667f67157c1a1aea7dc797a and < 0caa9f348f8b5356900de77b0bb89a697c4aff20
- affected>= 690afc165bb314354667f67157c1a1aea7dc797a and < 03d8843b143ebbbfaf48511922abc6e886575a61
- affected>= 690afc165bb314354667f67157c1a1aea7dc797a and < c38c8b0db3c65b597e7ece317b6cb59de3d15e69
- affected>= 690afc165bb314354667f67157c1a1aea7dc797a and < f00a50876d2818bd6dc86fa98b3ef360884c53c8
- affectedd0201d2405dac8d9b16773e97709925e397552d0
- affected7943bb0f06365cf5e32f3cf8a6b29eeae981fb8a
- affected>= 4.19.100 and < 4.20
- affected>= 5.4.16 and < 5.5
- affected5.5
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.