New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
Summary
A newly disclosed memory corruption vulnerability in the Linux kernel's Open vSwitch datapath, named OVSwrap (CVE-2026-64531), allows local users to gain root privileges. A public exploit supporting approximately 800 kernel builds has been released.
IFF Assessment
FOE
This vulnerability allows local users to escalate privileges to root, which is a significant risk for system security.
Severity
7.8
High
Defender Context
Defenders should prioritize patching systems that utilize Open vSwitch in the Linux kernel, especially those with default configurations, as this vulnerability provides a straightforward path to root escalation for local attackers. The availability of a public exploit increases the immediate risk of exploitation.