From nobody Sat Jul 25 18:01:40 2026 Received: from mail-wr1-f46.google.com (mail-wr1-f46.google.com [209.85.221.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 450943B71AF for ; Wed, 15 Jul 2026 05:56:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.46 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784095019; cv=none; b=i0X/sZ+yMN4Q6ZC6JYWvcFUj0dOAE+bBTD9ekrPvq/iiiWUTS7xiLWcU4biXq4t4BTp1rLD4wXAh82avgtwqHbO2qu5yvZ1n4hGWhBVNO9e8LeKHymGesOY+Sh38Yw0S0kyhGhLfyvVP75MzAxmeEOCihjXuTXQP4cS65+vQ4ds= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784095019; c=relaxed/simple; bh=mOnwR/pIE5XzBsYGILop0yuiJAAjA0tbnoT2QDJFZ1E=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=iJqxcq004deMj9naMkB1HsLjoJHsH5rAhxb1RPSDz0GNSA5gxbL+69r5RgUqjl5iwfeH8w3MiFoUTqm0e6DgjNwxsOwrQ1YUEIqqmJVQy67P1/IlEcaA95p7zGMd2n0bRhmj574c2hy4SzM4aaxO1fuOP2AkfAMtt283amV9mTE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=0sec.ai; spf=pass smtp.mailfrom=0sec.ai; dkim=temperror (0-bit key) header.d=0sec.ai header.i=@0sec.ai header.b=T5zrB1p9; arc=none smtp.client-ip=209.85.221.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=0sec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=0sec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=temperror (0-bit key) header.d=0sec.ai header.i=@0sec.ai header.b="T5zrB1p9" Received: by mail-wr1-f46.google.com with SMTP id ffacd0b85a97d-47f3b39f2a1so1184767f8f.2 for ; Tue, 14 Jul 2026 22:56:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=0sec.ai; s=google; t=1784095012; x=1784699812; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ZAOalb6etao4htQR6eohIIXgH1RFAxhgVjEFqDvisp4=; b=T5zrB1p9pSYg+XFfJLafCx2fFJHA3XWy+nVqPanzh+7SZpeZ1g2Lor7bUtUXp+8bk6 uT5IAAziQJwUND2o0ilr1l/A+rI4Nh+F2tnbFO/os1hdR6FsBbcKbAL75cAb0NpSA7u5 HbozE0ZGCBmtf84OzKBBjIJqpvoT9ZaiQ78Uv5wg21pEgmbQloVm90ysZpZv0Wl5Bl7I U5Li44VPWMEmmJMokJbicgk9e3mTeDoZ2T2zTBLOXtObgOaeMY/npLdW4wWj41kt1q5y W4JnMMtvt4pcLJxm5HtFouO/8RPbXz4hd9DOevIECH6z0Nn8ehQrG8ITC8FCr5uGufCN 7w7Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784095012; x=1784699812; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=ZAOalb6etao4htQR6eohIIXgH1RFAxhgVjEFqDvisp4=; b=fjo8wCWmn0/Ql28z8tQwFLvabaqwdoJCztDdmdIocJRuS+qCSfIfh5NByQeujbJmT5 2pz5fmtk+huM9GSFTpHE0Mrf7PPRA8syixKBv/1k44TjnbgV5qy4AsTsmXmp26+qN8J4 Ggb/DSlVI+n4gnpOh2wY7FwH7pUCy8I5CYUHiL2aQKFaFYaZpVu31pIqWyvuGJy5XGHk hWklEc10hXBOW/MkkArqea8MJUir+zmxzYD9jWk2bLO+0npqRyiTbdn0wkqeJu7Y1zGH NKmWPFddHdPXUKIyH3SC8mnYQyd4z1k1ucXt1rDUWk7QI2nSu5EEs2rPTazl2RVEz/01 ZoYQ== X-Forwarded-Encrypted: i=1; AHgh+Rqbp3CzjaF76AT1OxwK6tFz+3Qe6mE+yD5YMFrc63WBj3rQSV6Kl7FhGDq/DjztdXUo3EZrMtb5OJiyiOo=@vger.kernel.org X-Gm-Message-State: AOJu0YxDhl37ASQ90u0zezGsbjhoEANMt3SpyMIX2Wj4gJ2fMbQiHYWL eCTMsaD9OqFRTIwJ8ETGwAsIESqQtR1jvnqC1Oiuq6sim9LBbzKy0A4Bv8PyGysGD5/9 X-Gm-Gg: AfdE7ckEGK1F8RG2VlQ58XSRp4Spfo4LHoqO3jx8HPkeM45q6qyYX9sg5gyw8MneKwF OoR12hDezcAwZcu79ph12MxeIYC1hNgDZgOvnq/bhByC3DtDUHhbG/tEhIkYBCjPY8QLu7zRIhC iWvEbiHJYo9u7viEz65bcTwTAeFOT78tsiBnGxDV9CoGy8XzsV8cISPsJ8sEDXVtAk4+L1tVtsc cWoRfDsdRy2KFPsl30rS/klfu4LLQYT2krPzUsfwEk8jOyQi89R6icDfAd/ymcBccpN8hLm2PQl 5QqLyOEI/fjVbt+UjAdYU4H5VFQ578MkvDjd/ACrD7E3lyUfvmEZPCEWD2wKynumw0WcQy52D06 kCczHU0I8Muc6mZiKyy+C7QLSSArJELsE37Dz8SNCVyLidxoxwwb09+xF25/v0Fa3dCGW/aLl5j OGmdLOHEz7trgv/rhoTG6fxIiibjogY36mMxVCz+ffeswWzKDf/6p5MdLpBzxjAMMkOYIsHiuYw 63cKh5q8SqH3OI7BVZdFwx9Kga06jlaBBA= X-Received: by 2002:a5d:5d12:0:b0:472:4861:5d4d with SMTP id ffacd0b85a97d-47f2dcc35e6mr17464772f8f.23.1784095012002; Tue, 14 Jul 2026 22:56:52 -0700 (PDT) Received: from PeakBook-Mini.tail8e484.ts.net ([178.197.218.188]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f4635082csm14220369f8f.7.2026.07.14.22.56.50 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Tue, 14 Jul 2026 22:56:51 -0700 (PDT) From: Doruk Tan Ozturk To: davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, andrew+netdev@lunn.ch Cc: sd@queasysnail.net, linville@tuxdriver.com, mschiffer@universe-factory.net, maoyixie.tju@gmail.com, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH net 1/2] vxlan: require CAP_NET_ADMIN in the device netns for changelink Date: Wed, 15 Jul 2026 07:56:47 +0200 Message-ID: <20260715055648.33060-2-doruk@0sec.ai> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260715055648.33060-1-doruk@0sec.ai> References: <20260715055648.33060-1-doruk@0sec.ai> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" A tunnel changelink() operates on at most two netns, dev_net(dev) and the sticky underlay netns vxlan->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in vxlan->net can rewrite a vxlan device whose underlay lives in vxlan->net. vxlan_changelink() validates and applies the new configuration against vxlan->net (vxlan_config_validate(vxlan->net, ...)) and can reopen the underlay socket in that netns, so the same reasoning as the tunnel changelink series applies here. Gate vxlan_changelink() with rtnl_dev_link_net_capable(), at the top of the op before any attribute is parsed, matching ipgre_changelink() and the rest of the "require CAP_NET_ADMIN in the device netns for changelink" series. Found by 0sec automated security-research tooling (https://0sec.ai). Fixes: 889ce937c98f ("vxlan: correctly set vxlan->net when creating the dev= ice in a netns") Cc: stable@vger.kernel.org Assisted-by: 0sec:multi-model Signed-off-by: Doruk Tan Ozturk --- drivers/net/vxlan/vxlan_core.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/net/vxlan/vxlan_core.c b/drivers/net/vxlan/vxlan_core.c index 67c367cc5662..d834a4865aec 100644 --- a/drivers/net/vxlan/vxlan_core.c +++ b/drivers/net/vxlan/vxlan_core.c @@ -4421,6 +4421,9 @@ static int vxlan_changelink(struct net_device *dev, s= truct nlattr *tb[], struct vxlan_rdst *dst; int err; =20 + if (!rtnl_dev_link_net_capable(dev, vxlan->net)) + return -EPERM; + dst =3D &vxlan->default_dst; err =3D vxlan_nl2conf(tb, data, dev, &conf, true, extack); if (err) --=20 2.43.0 From nobody Sat Jul 25 18:01:40 2026 Received: from mail-wr1-f51.google.com (mail-wr1-f51.google.com [209.85.221.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D96673B7770 for ; Wed, 15 Jul 2026 05:56:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.51 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784095018; cv=none; b=lkmFY+3Nl54qs3BWUZHt1kQfN9a5qUd/1KytcIImLXejYMm9uQUiOB7+yEI8VcIppLv9Ow2ddDt1Qi+4av+ek9BU9V4SAGZNLfUn9W9ZfqTDTuZgKb1BFy5a75OsMncqZdXTfsZK6NAnRqULfzli1rarEMcsT88ZvPFIh1lJo+0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784095018; c=relaxed/simple; bh=esL/43unqiNUkBr/Ljva6pP91lPf4vb7RyxAP1zl12c=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Fx3dXir0aEvA7Sh7/qVdIEnfghh4CCMAhf7hYJC/OCpSqeAsORBpv5zbKKUUhiw1rv2fX1KWfEhceUOPpsm6Tua+U3eP0bM4kO1+YWU+V5EZoXwrzY3QG+NGNTobBLjOzLwaziYByOOH4QLYjVu9n+jCIVzZm6Q7vEIohvbqSz0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=0sec.ai; spf=pass smtp.mailfrom=0sec.ai; dkim=temperror (0-bit key) header.d=0sec.ai header.i=@0sec.ai header.b=nCsoSLEc; arc=none smtp.client-ip=209.85.221.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=0sec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=0sec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=temperror (0-bit key) header.d=0sec.ai header.i=@0sec.ai header.b="nCsoSLEc" Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-47f36a122fdso1798640f8f.2 for ; Tue, 14 Jul 2026 22:56:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=0sec.ai; s=google; t=1784095013; x=1784699813; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=iueURVe0vlYIqUuAsBfvKYIJESyK+6jqiIp58cwZiM8=; b=nCsoSLEcjUE3qQ+jpRtBiSHZz+xWcrG9vjTNkYWF1V+0mZyK5KTd4njN7WY7qhetK/ OLV6TrS5aBpEU7A3jLAubLcnSjYMHarXfQbbisTm2KEqGGAWfCnBmDGEa4/+zKr4ILNz oPrCPXvXflKVHA7+LJxKIxO4Wxw4/gpeRdhelvUv61j7S5qgGf31y0f07LaOTg2j9yPR SkeWsn18bLqGp/luj9vQw8oV3AWWt9clqvFOGVXZT892pz7yuPMDwF5jezGjLXJiU4Bs celWm3mRxtVW7t3XZ6kCAVqh7DFWhV6u4YfvXnLGkzXFGh5KbFl6n1KNbqEGCaynF5Xv pePA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784095013; x=1784699813; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=iueURVe0vlYIqUuAsBfvKYIJESyK+6jqiIp58cwZiM8=; b=UKv3rCWV4L2F2XHdf7DbzBladJ1YCzSX5V76/ZdHo1FYOgHf0wYqBAgAzieHOWynnq X3vz9/AZXw+AdwVib+Yxc9haPK6SnLnv+IUDE89UTO58X6Nix4ZSTBvVtZiW5CCiJu+8 8Xj2Sr8mjjmTZ1bFq1QPv3VZnOP9mACIKnTRKdqjasFVzZfh8cUmtIT8iPQk90oxyJUZ cmQo6L1SyBlJEH5gutYMFCYPICHC5U1HnoJ/4PGnUF4g//78ljzPrIuYu2CxMrNcQOVw ZKbx3RgNat/F4+Gt7iHy/s1k6NZwBhZE8BYB8hJpQUkw8RCCFBD8bKiSc0VFzplvd5wo 7eEA== X-Forwarded-Encrypted: i=1; AHgh+Rribnte7g189S5rdv8yvTFcRHaNGcvlEntmEnmA/qcAYp1eZg15SURfcnCAkdWiUGZHGymQ7A3u/LcT3Gc=@vger.kernel.org X-Gm-Message-State: AOJu0YwyOR6K0qomPZbOtaddQRV73i0EPykNYQKCqrbWOHGB+ziE3BiW FO5I2qVr498DvZ6T6lJ5W4z2ulU9l0XIBZg9YaA09uEVzLRZN32oyirX3GOWmgGoDtgK X-Gm-Gg: AfdE7cnvlDegZvmwPM6Bt4c/FA+Ej/15XMCvh1QTPQel1sUDzKFp9/iKXML0Z45V1ds nS80dZGjMODVYO7084/zWMMBj5FUJTUKz2H1CEwwBtVQAnCzdPzjjyT6XHpkTDCu+OulaICZ0WC UDxK2E6dwp2xQchRtAHV6oaOOTEUvJLGK0jNtzBWtYloQXSlFJnHaowN2C6HrAmC04W/4UzsOeZ 1/MiVHxzLQtnG2v2tyCsqG7LOQHQ/MIR+x8XBbJvvqQK8Q6ndU6ftRibQdqDRM/Jiewst9DWxkw N0jqjuP+P95cI5HmuZx+VJCpLQL87M9p6vdtUNjwEpLWYoS/RR4Tj6eN1FsAIUYWBMVF+bqpEhW LRhzVAfCK0HUIAtfDZC4KMAd6ekajtEf0PveisNjF5UAtGewwVsqDPh8S57dpB4Ig5eya8fCSYO m0zFdwMy6VrBXBw2X+FPkQvqMOX2NAGx/Y0sJ43veMDI3HlcszhVUZ09PqUELKie+Mdlfn9mX+I FNEY/8IA7OiDkGecrooQSEBzKrgSo5jjJQ= X-Received: by 2002:a5d:59c7:0:b0:461:a16c:a5f4 with SMTP id ffacd0b85a97d-47f2dd1f29emr18774517f8f.33.1784095013281; Tue, 14 Jul 2026 22:56:53 -0700 (PDT) Received: from PeakBook-Mini.tail8e484.ts.net ([178.197.218.188]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f4635082csm14220369f8f.7.2026.07.14.22.56.52 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Tue, 14 Jul 2026 22:56:52 -0700 (PDT) From: Doruk Tan Ozturk To: davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, andrew+netdev@lunn.ch Cc: sd@queasysnail.net, linville@tuxdriver.com, mschiffer@universe-factory.net, maoyixie.tju@gmail.com, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH net 2/2] geneve: require CAP_NET_ADMIN in the device netns for changelink Date: Wed, 15 Jul 2026 07:56:48 +0200 Message-ID: <20260715055648.33060-3-doruk@0sec.ai> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260715055648.33060-1-doruk@0sec.ai> References: <20260715055648.33060-1-doruk@0sec.ai> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" A tunnel changelink() operates on at most two netns, dev_net(dev) and the sticky underlay netns geneve->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in geneve->net can rewrite a geneve device whose underlay lives in geneve->net. geneve_changelink() applies the new configuration against geneve->net: geneve_link_config() and the geneve_quiesce()/geneve_unquiesce() pair reopen the underlay sockets in that netns (geneve_sock_add() uses geneve->net), so the same reasoning as the tunnel changelink series applies here. Gate geneve_changelink() with rtnl_dev_link_net_capable(), at the top of the op before any attribute is parsed, matching ipgre_changelink() and the rest of the "require CAP_NET_ADMIN in the device netns for changelink" series. Found by 0sec automated security-research tooling (https://0sec.ai). Fixes: 2d07dc79fe04 ("geneve: add initial netdev driver for GENEVE tunnels") Cc: stable@vger.kernel.org Assisted-by: 0sec:multi-model Signed-off-by: Doruk Tan Ozturk --- drivers/net/geneve.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/net/geneve.c b/drivers/net/geneve.c index 396e1a113cd4..03c99a016298 100644 --- a/drivers/net/geneve.c +++ b/drivers/net/geneve.c @@ -2376,6 +2376,9 @@ static int geneve_changelink(struct net_device *dev, = struct nlattr *tb[], struct geneve_config cfg; int err; =20 + if (!rtnl_dev_link_net_capable(dev, geneve->net)) + return -EPERM; + /* If the geneve device is configured for metadata (or externally * controlled, for example, OVS), then nothing can be changed. */ --=20 2.43.0