Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
- >= 5.15, < 5.15.0-rc1
A vulnerability in the Linux kernel's Virtual Tunnel Interface version 6 (VTI6) management can lead to unauthorized packet injection across different tenant spaces on container hosts. This issue arises because the VTI6 tunnel update process does not correctly handle network namespace migrations, allowing an unprivileged user to manipulate tunnel parameters and intercept packets through a controlled network device.
Exploitation of this vulnerability enables cross-tenant packet injection on container hosts, potentially allowing an attacker to intercept and manipulate network traffic between containers.
The vulnerability can be reproduced by creating a VTI6 tunnel and then migrating it to a different network namespace using the IFLA_NET_NS_FD interface. After the migration, the 'SIOCCHGTUNNEL' command can be issued on the tunnel, which will trigger the vulnerability by causing the tunnel management process to reference the wrong network namespace. This misalignment allows for the interception of packets through a device that the attacker controls.
Users can apply the latest patches available in the Linux kernel stable tree to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.