ip6_vti: set netns_immutable on the fallback device.
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.1%
exploitation probability
0.1%top 98% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
ip6_vti: set netns_immutable on the fallback device.
john1988 and Noam Rathaus reported that vti6_init_net() does not set the
netns_immutable flag on the per-netns fallback tunnel device (ip6_vti0).
Other similar tunnel drivers (like ip6_tunnel, sit, ip6_gre, and ip_tunnel)
correctly set this flag during their fallback device initialization to
prevent them from being moved to another network namespace.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/12acc977838c943636fb01e2f3087d2e4cc3b7cchttps://git.kernel.org/stable/c/12c65e2c7fef507551bd7b52123598a761662c01https://git.kernel.org/stable/c/7f28e3948c59481f8db9c9638e204258d26b4e41https://git.kernel.org/stable/c/c5dbd669db5a426b3025512322e1bf2cdbe14305https://git.kernel.org/stable/c/d289d5307762d1838aaece22c6b6fcad9e8865f9https://git.kernel.org/stable/c/dcdce3bc9f08026ff3739ee7339e1bef526fc5f3https://git.kernel.org/stable/c/ecf8904067dcba0dad86ece80874841e60317885https://git.kernel.org/stable/c/f4b6b4af7ef0661ac153c6f7eb1030aa8482c1a3