A newly disclosed Linux kernel local privilege escalation flaw, CVE-2026-64531 or OVSwrap, allows unprivileged local users to obtain root by exploiting the Open vSwitch kernel datapath. The bug stems from improper handling of nested Netlink action lengths, where a 16-bit length field can wrap beyond 65,535 bytes and cause the kernel to interpret attacker-controlled data as valid actions, leading to deterministic memory corruption. Reports say the issue is broadly exploitable across many default Linux distributions and can be reached from an unprivileged user and network namespace with CAP_NET_ADMIN inside that namespace.
Public reporting says exploitation is unusually practical because it requires no memory grooming and no pre-existing OVS bridge or daemon, while a proof of concept reportedly supports about 800 x86-64 kernel builds. The flaw became easier to exploit after Open vSwitch removed a 32 KB action-size limit in 2025, exposing a long-hidden integer truncation bug. Patched stable kernel releases are available, and defenders are being urged to prioritize vendor kernel updates, blacklist or prevent loading of the openvswitch module where it is not needed, restrict unprivileged user namespaces where feasible, and consider temporary eBPF/BPF-based mitigations until systems are updated.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
A 2025 change in Open vSwitch removed a long-standing action-size limit of roughly 32 KB, making a previously latent length-handling flaw in the kernel datapath practically exploitable. Both references state the underlying vulnerable code had existed for about 13 years before this change.
A public proof of concept was reported that supports roughly 800 x86-64 kernel builds and demonstrates exploitation across many default Linux distributions. The references say the exploit can work without a pre-existing OVS bridge or running ovs-vswitchd and can be reached from user and network namespaces.
Security researcher Asim Manizada disclosed CVE-2026-64531, dubbed OVSwrap, a Linux kernel local privilege-escalation vulnerability in the Open vSwitch datapath. The flaw allows an unprivileged local user to gain root privileges under common conditions by abusing a 16-bit Netlink length wraparound.
Before public disclosure, the Linux kernel community released stable kernel updates addressing CVE-2026-64531. One reference identifies the first corrected versions as 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethecybersecguru.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.