OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root
ID: b2f47b29-5eb6-5c65-8042-4ff3c7dbeb09
STIX ID: report--b2f47b29-5eb6-5c65-8042-4ff3c7dbeb09
Feed Name: Security Affairs
OVSwrap (CVE-2026-64531) is a 13-year-old Open vSwitch datapath bug in the Linux kernel that enables reliable local privilege escalation to root via a 16-bit Netlink attribute length wraparound; an upstream fix shipped on July 24 and a public PoC with prebuilt records for ~800 kernels is available. The issue became exploitable after removal of a 32 KiB generation cap, and an unprivileged user namespace (common default) is sufficient to reach the vulnerable code; recommended mitigations include installing patched vendor kernels, blocking module loads (e.g. `echo 'install openvswitch/bin/false' >/etc/modprobe.d/ovswrap.conf`), disabling unprivileged user namespaces, or deploying the provided emergency BPF guard.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
