New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
Overview
A newly discovered vulnerability in the Linux kernel's Open vSwitch datapath allows local users to gain root access on several default-configured distributions. This memory corruption flaw, identified as CVE-2026-64531 and given the codename OVSwrap, has a CVSS score of 7.8, indicating a high severity. Security researcher Asim disclosed this issue, which comes with a public exploit that has pre-built records for about 800 different kernel builds. This broad impact means that many users could be affected if they have systems running these vulnerable kernel versions. Companies and system administrators should take immediate action to assess their environments and apply necessary patches to mitigate this risk.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Linux kernel versions with Open vSwitch enabled across various default-configured distributions, approximately 800 kernel builds affected.
- Action Required: System administrators should apply patches for the Open vSwitch component in the Linux kernel as soon as they become available.
- Timeline: Newly disclosed
Original Article Summary
A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds. The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by security researcher Asim
Impact
Linux kernel versions with Open vSwitch enabled across various default-configured distributions, approximately 800 kernel builds affected.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
System administrators should apply patches for the Open vSwitch component in the Linux kernel as soon as they become available. Users are advised to review their kernel configurations and disable Open vSwitch if it is not needed. Regular updates and monitoring for any security patches related to CVE-2026-64531 should be prioritized.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Linux, CVE, Exploit, and 1 more.