news.mlab.sh
Back to the feed
vulnerability

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

Critical
Image: The Hacker News
Summary

A critical memory corruption vulnerability (CVE-2026-64531) in the Linux kernel's Open vSwitch datapath allows local users to gain root access on a wide range of distributions. The vulnerability stems from a 16-bit length field in Netlink attributes, leading to a 65,535 byte limit that was removed in 2025, creating a path for attackers to exploit through crafted Netlink actions. The exploit chain leverages a memory corruption vulnerability to leak kernel pointers, read arbitrary kernel memory, and ultimately achieve root privileges. The vulnerability has been demonstrated on numerous Linux distributions, including AlmaLinux, Ubuntu, Debian, and Rocky Linux.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.