Unrated severityNVD Advisory· Published Jun 19, 2026
ip6_vti: set netns_immutable on the fallback device.
CVE-2026-52909
Description
In the Linux kernel, the following vulnerability has been resolved:
ip6_vti: set netns_immutable on the fallback device.
john1988 and Noam Rathaus reported that vti6_init_net() does not set the netns_immutable flag on the per-netns fallback tunnel device (ip6_vti0).
Other similar tunnel drivers (like ip6_tunnel, sit, ip6_gre, and ip_tunnel) correctly set this flag during their fallback device initialization to prevent them from being moved to another network namespace.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13- osv-coords12 versionspkg:apk/chainguard/linux-aws-6.12pkg:apk/chainguard/linux-azure-6.12pkg:apk/chainguard/linux-azure-6.18pkg:apk/chainguard/linux-gcp-6.12pkg:apk/chainguard/linux-gcp-6.18pkg:apk/chainguard/linux-gcp-6.18-bootc-boot-installedpkg:apk/chainguard/linux-qemu-6.12pkg:apk/chainguard/linux-qemu-6.18pkg:apk/chainguard/linux-qemu-6.18-bootc-boot-installedpkg:apk/chainguard/linux-qemu-melangepkg:apk/chainguard/linux-vmware-6.12pkg:linux/kernel
< 6.12.96-r0+ 11 more
- (no CPE)range: < 6.12.96-r0
- (no CPE)range: < 6.12.96-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.12.96-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.12.96-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.12.96-r0
- (no CPE)range: >= 3.15.0, < 5.10.260
Patches
Vulnerability mechanics
References
3News mentions
1- Linux Kernel: Three CVEs Disclosed June 19 — BPF, VTI, and RDMA FixesVypr Intelligence · Jun 19, 2026