CVE-2026-72055
Linux kernel VTI IPv6 changelink flaw allows cross-netns tunnel modification
Is CVE-2026-72055 being exploited?
Not confirmed. CVE-2026-72055 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.17% probability of exploitation in the next 30 days.
How severe is CVE-2026-72055?
CVE-2026-72055 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72055?
Yes. A fix has been recorded for CVE-2026-72055. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72055 affect?
CVE-2026-72055 affects Linux kernel - net: ip6_vti (vti6_changelink), Kernels with VTI IPv6 tunnel support. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72055?
Apply vendor kernel updates or backport patch; audit and restrict CAP_NET_ADMIN assignments.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local privilege/namespace breach: attacker with CAP_NET_ADMIN in one netns can modify tunnel links in another netns, enabling network tampering or privilege escalation.
Immediate action required
- affected>= 61220ab349485d911083d0b7990ccd3db6c63297 and < f5254e7766b4ac02b66b2ccef896cd278503cb11
- affected>= 61220ab349485d911083d0b7990ccd3db6c63297 and < ef897249dc957089e6f7f11ceea699e093ad51bd
- affected>= 61220ab349485d911083d0b7990ccd3db6c63297 and < f6e8b52a2cb3bbd72ddc2d44e474b907b9dcf5ba
- affected>= 61220ab349485d911083d0b7990ccd3db6c63297 and < c64b9ae7eb97e81d54b792910a3aeafd92566c79
- affected>= 61220ab349485d911083d0b7990ccd3db6c63297 and < b2b61c540571b3cc2f461e2a579ba2cc8c2a52cf
- affected>= 61220ab349485d911083d0b7990ccd3db6c63297 and < 0b2f9c908f930ec4be17d389723f9a202d6a883c
- affected>= 61220ab349485d911083d0b7990ccd3db6c63297 and < f97e93ebf2f9b8ef3b87f7a9371255e84d151587
- affected>= 61220ab349485d911083d0b7990ccd3db6c63297 and < e2ac3b242c37dff323a964962e43854f4b1a2b79
- affected3.15
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.