Database/Control plane, storage & DevOps
Linux VXLAN driver (CAP_NET_ADMIN check on changelink across netns): A VXLAN tunnel's `changelink()` operates across
Impact
A VXLAN tunnel's changelink() operates across two network namespaces — the device's namespace and the sticky underlay namespace — but the capability check only covers the device's. Once a VXLAN device has been created in or moved to a different namespace, a caller with CAP_NET_ADMIN in only one of them can reconfigure the tunnel's underlay side. In a container platform, network namespaces are the tenant boundary and CAP_NET_ADMIN inside a namespace is something you grant routinely; this turns namespace-local privilege into control over the underlay encapsulation that other tenants share.
Who can reach it
A container or tenant holding CAP_NET_ADMIN in its own network namespace, against a VXLAN device whose underlay namespace differs from its device namespace.
What to do
Kernel upgrade plus host reboot across container hosts. Interim: do not grant CAP_NET_ADMIN to tenant containers — a container-runtime policy change and one of the highest-value single restrictions available on a shared GPU host, since it also closes a long tail of similar netlink-reachable issues.
References
Related entries
- Jenkins Multijob Plugin: Groovy features skip Script Security, giving job configurers controller RCECVE-2026-70431 · Jenkins Multijob Plugin (Groovy scripting outside Script Security)High
- Jenkins Multijob Plugin: CSRF lets an attacker run code in the Jenkins controller JVMCVE-2026-70432 · Jenkins Multijob Plugin (CSRF on code-executing endpoint)High
- Linux octeontx2-af (Marvell OCTEON CN10K, LMTLINE mailbox handler): The OCTEON CN10K admin-function mailbox handlerCVE-2026-72045 · Linux octeontx2-af (Marvell OCTEON CN10K, LMTLINE mailbox handler)High
- Linux octeontx2-af (VF clobbering shared CGX PKIND state): PF and VF NIX logical functions that share a CGX MAC reuseCVE-2026-74527 · Linux octeontx2-af (VF clobbering shared CGX PKIND state)High
- SkyPilot (API server, service account role update authorization): SkyPilot never checks whether the caller is entitledCVE-2026-75481 · SkyPilot (API server, service account role update authorization)High
- Citrix NetScaler ADC/Gateway: memory overflow in Gateway and AAA vservers causes denial of serviceCVE-2026-8452 · Citrix NetScaler ADC / Gateway (Gateway and AAA virtual servers)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.