A 13-year-old Linux kernel vulnerability, known as OVSwrap, has been discovered, allowing local users to gain root privileges on most distributions that utilize Open vSwitch. The flaw, designated as CVE-2026-64531 with a CVSS score of 7.8, affects the Linux kernel's Open vSwitch datapath, enabling an ordinary user to become root on a wide range of default-configured distributions1. A proof-of-concept exploit has been made public, including pre-built records for approximately 800 kernel builds. The upstream fix was shipped in stable trees on July 24, providing a patch for the vulnerability. This disclosure expands the active attack surface, making it essential for practitioners to prioritize mitigation based on their exposure and exploitation evidence. The vulnerability's long existence and widespread impact make it a significant concern for Linux users, emphasizing the need for prompt patching and vigilance.
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root
⚡ High Priority
Why This Matters
CVE-2026-64531 disclosure expands the active attack surface — prioritize based on your exposure and exploitation evidence.
References
- SecurityAffairs. (2026, August 5). OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root. *SecurityAffairs*. https://securityaffairs.com/196657/hacking/ovswrap-13-year-old-linux-kernel-flaw-lets-local-users-become-root.html
Original Source
SecurityAffairs
Read original →