A critical memory corruption vulnerability, identified as CVE-2026-64531, has been discovered in the Linux kernel's Open vSwitch datapath, allowing local users to escalate their privileges to root on a wide range of default-configured distributions. This flaw, dubbed OVSwrap, has a CVSS score of 7.8, indicating a high level of severity. A public exploit is already available, complete with pre-built records for approximately 800 kernel builds, making it easier for attackers to target vulnerable systems. The vulnerability was disclosed by a security researcher and is considered a significant threat due to its potential for widespread exploitation1. The existence of this vulnerability expands the active attack surface, making it essential for practitioners to prioritize mitigation based on their exposure and evidence of exploitation. This vulnerability matters to security professionals because it highlights the need for prompt patching and monitoring of Linux systems to prevent potential root compromises.
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
⚡ High Priority
Why This Matters
CVE-2026-64531 disclosure expands the active attack surface — prioritize based on your exposure and exploitation evidence.
References
- The Hacker News. (2026, August 5). New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch. *The Hacker News*. https://thehackernews.com/2026/08/new-ovswrap-linux-kernel-flaw-lets.html
Original Source
The Hacker News
Read original →