Researchers disclosed a deterministic Linux local privilege-escalation primitive affecting Open vSwitch forwarding paths, tracked as CVE-2026-90049, CVE-2026-89487, and CVE-2026-80977. A failed Open vSwitch userspace upcall can invoke skb_tx_error() on an skb that remains in use, clearing ownership metadata while page-cache fragments remain attached. An unprivileged user able to create user namespaces and administer networking within their own namespace can combine MSG_ZEROCOPY, an attacker-controlled OVS datapath, and ESP-in-UDP handling to write chosen plaintext into read-only, root-owned file page-cache pages before ESP authentication fails.
The transient page-cache modification can alter an in-memory setuid-root binary and produce root privileges when that program executes. Default deployments of Arch Linux, Fedora, Debian, Amazon Linux, and Red Hat Enterprise Linux may be exposed where unprivileged user namespaces are enabled, Open vSwitch autoloads, and kernels contain the relevant Fragnesia changes. Fixes have landed upstream and began reaching stable kernels; organizations should apply vendor kernel updates and, pending patching, disable unprivileged user namespaces or prevent Open vSwitch and ESP module autoloading where operationally feasible.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
The remediation, consisting of three patches including a change to preserve shared-SKB state in skb_tx_error(), landed in mainline and began shipping in stable kernels. Organizations were advised to apply their distribution kernel updates for CVE-2026-90049, CVE-2026-89487, and CVE-2026-80977.
The Open vSwitch/ESP issue, characterized as a bypass of protections for Fragnesia (CVE-2026-46300), was publicly discussed on the netdev mailing list.
The Open vSwitch forwarding-path flaws tracked as CVE-2026-90049, CVE-2026-89487, and CVE-2026-80977 were reported to the Linux kernel security team. The issue could allow a local attacker with unprivileged user and network namespaces to alter root-owned file page-cache contents through Open vSwitch and ESP processing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.