< Back to all clusters
[TECHNOLOGY] · Brazil · 2 sources

started · updated

Open vSwitch Kernel Flaw (OVSwrap) Enables Local Root Escalation

Security researcher Asim Manizada disclosed a 13‑year‑old flaw in the Linux kernel’s Open vSwitch datapath (CVE‑2026‑64531). The vulnerability allows a local, unprivileged user to trigger a length‑field wraparound, forging action headers that grant root privileges on a wide range of default‑configured Linux distributions.

The upstream fix was released to stable trees on July 24, and a proof‑of‑concept exploit covering roughly 800 kernel builds has been published. Systems that have not yet applied the patch—especially servers, virtual machines, containers and cloud environments that use Open vSwitch—are urged to update immediately to prevent full system compromise.

Entities

Asim Manizada · Linux kernel · Open vSwitch

Sources

about 1 month ago