logo

OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root

ID: b2f47b29-5eb6-5c65-8042-4ff3c7dbeb09

STIX ID: report--b2f47b29-5eb6-5c65-8042-4ff3c7dbeb09

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-08-05

Date Updated: 2026-08-06

Author: Pierluigi Paganini

...
...

OVSwrap (CVE-2026-64531) is a 13-year-old Open vSwitch datapath bug in the Linux kernel that enables reliable local privilege escalation to root via a 16-bit Netlink attribute length wraparound; an upstream fix shipped on July 24 and a public PoC with prebuilt records for ~800 kernels is available. The issue became exploitable after removal of a 32 KiB generation cap, and an unprivileged user namespace (common default) is sufficient to reach the vulnerable code; recommended mitigations include installing patched vendor kernels, blocking module loads (e.g. `echo 'install openvswitch/bin/false' >/etc/modprobe.d/ovswrap.conf`), disabling unprivileged user namespaces, or deploying the provided emergency BPF guard.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.