Researchers disclosed OVSwrap (CVE-2026-64531), a local privilege-escalation flaw in the Linux kernel's Open vSwitch datapath that can let an unprivileged user gain root code execution on affected systems. The bug occurs when Open vSwitch expands validated userspace actions into larger internal Netlink attributes and a generated nested attribute exceeds 65,535 bytes, causing the 16-bit nla_len field to wrap and later parsers to trust a corrupted length. The issue is exploitable when the OVS kernel datapath and conntrack/FTP-helper support are present and either unprivileged user or network namespaces are enabled, or an attacker controls a network namespace with CAP_NET_ADMIN.
The disclosure said a proof of concept can use attacker-controlled conntrack labels and timeout names to forge actions, leak kernel pointers, read kernel memory, alter targeted values, corrupt host process credentials, and ultimately write a sudoers rule for root execution. Upstream fixes were released in commit 3f1f75536668 and shipped in stable kernels 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5. The reports identified multiple stock-default exploitable distributions, including Ubuntu 22.04/24.04, Debian 12/13, Fedora 42-44, Arch Linux, AlmaLinux, Rocky Linux, NixOS, and Kali Linux, and recommended mitigations such as unloading or blocking the openvswitch module, disabling unprivileged user namespaces, or applying an emergency BPF-based mitigation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Asim Manizada published a write-up on OVSwrap describing the Linux kernel Open vSwitch local root vulnerability. The post is referenced as a source alongside the later oss-security disclosure.
The OVSwrap flaw, tracked as CVE-2026-64531, was originally reported to security@kernel.org and Open vSwitch maintainers. The bug can enable local privilege escalation to root on affected Linux systems using the OVS kernel datapath.
A March 2025 change removed the previous 32 KiB cap on Open vSwitch's generated internal action stream. The disclosure says this allowed generated nested attributes to exceed 64 KiB and exposed the missing length check that underlies OVSwrap.
Asim Manizada disclosed OVSwrap publicly on oss-security after the linux-distros embargo expired. The disclosure included technical details, proof-of-concept behavior, affected distributions, and mitigations such as unloading the openvswitch module, disabling unprivileged user namespaces, or using an emergency BPF mitigation.
Upstream published the fix as commit 3f1f75536668, titled "net: openvswitch: reject oversized nested action attrs." The disclosure says the first fixed stable kernel releases were 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethehackernews.com
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceheyitsas.im
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.