OVSwrap is a local privilege escalation vulnerability in the Linux kernel Open vSwitch datapath caused by improper handling of oversized nested Netlink action attributes. Open vSwitch serializes generated flow actions as Netlink attributes whose nla_len field is 16 bits wide. After a 2025 change removed a prior total action-stream size guard, the kernel could generate nested action containers larger than 65,535 bytes without rejecting them. When such a container is closed, its length is truncated into the 16-bit nla_len field, producing a structurally inconsistent action stream. Subsequent dump or teardown paths then parse the stream using the wrapped length and can resume interpretation from attacker-controlled bytes inside the generated buffer, treating them as independent actions. The issue is particularly associated with oversized nested CLONE and conntrack-related actions and results in deterministic kernel memory corruption in the Open vSwitch action-processing path.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 5 candidates as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
58 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A local privilege escalation vulnerability in Linux kernel environments using Open vSwitch, caused by an unsafe assignment in Netlink attribute handling that can trigger length wraparound, memory corruption, arbitrary kernel read/write, and root privilege escalation.
A memory overflow vulnerability in the Linux kernel Open vSwitch module that can allow an authenticated local attacker to overwrite kernel memory, leading to local privilege escalation to root or disclosure of sensitive system information.
A local privilege escalation vulnerability in the Linux kernel's Open vSwitch (OVS) datapath caused by a 16-bit Netlink attribute length truncation/wraparound, enabling deterministic kernel memory corruption and root privilege escalation.
A local privilege escalation vulnerability in the Linux kernel Open vSwitch datapath caused by a 16-bit Netlink attribute length wraparound, allowing local users to gain root privileges on many Linux distributions using Open vSwitch.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.