[PATCH net v2 0/2] vxlan, geneve: require CAP_NET_ADMIN in the device netns for changelink

From: Doruk Tan Ozturk

Date: Thu Jul 16 2026 - 16:35:16 EST


The recent series "require CAP_NET_ADMIN in the device netns for
changelink" (8165f7ff57d9..27ccb68e7ccc) added rtnl_dev_link_net_capable()
and gated the eight IP tunnel drivers (ip_gre, ipip, ip_vti, ip6_tunnel,
ip6_gre, ip6_vti, sit, xfrm_interface). VXLAN and GENEVE share the exact
same shape but were not covered: both store the underlay netns sticky at
newlink (vxlan->net / geneve->net) and their changelink() operates on that
netns, while the generic RTM_NEWLINK path only checks CAP_NET_ADMIN against
dev_net(dev). Once such a device is created in or moved to another netns,
a caller privileged in dev_net(dev) but not in the underlay netns can
reconfigure the tunnel'"'"'s underlay.

This completes that series for the two UDP tunnel drivers that were left
out. Same helper, same placement (top of changelink, before any attribute
is parsed).

Verified on next-20260714 in QEMU with CONFIG_VXLAN=y + CONFIG_USER_NS=y:
an unprivileged user namespace holding CAP_NET_ADMIN only in a child netns
issues an IFLA_INFO_DATA changelink on a vxlan device whose underlay lives
in init_net. Before: returns 0 (reconfigures the init_net underlay).
After: returns -EPERM.

v2:
- Correct the Fixes: tag on both patches to the commit that added
changelink support (8bcdc4f3a20b for vxlan, 5b861f6baa3a for geneve),
as pointed out by Fernando Mancera. No code changes.

Doruk Tan Ozturk (2):
vxlan: require CAP_NET_ADMIN in the device netns for changelink
geneve: require CAP_NET_ADMIN in the device netns for changelink

drivers/net/geneve.c | 3 +++
drivers/net/vxlan/vxlan_core.c | 3 +++
2 files changed, 6 insertions(+)


base-commit: cc2b5f627e8ccbae1188ef2d8be3e451d7f933a5
--
2.43.0