Securityaffairs.Co
Critical OVSwrap Flaw in Linux Kernel Allows Local Root Access
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A 13-year-old vulnerability, CVE-2026-64531, known as OVSwrap, has been disclosed, allowing local users to gain root privileges on various Linux distributions using Open vSwitch. Security researcher Asim Manizada revealed that the flaw affects a wide range of systems and has a CVSS score of 7.8. A public exploit is available, which includes offsets for approximately 800 x86-64 kernel builds. The exploit can be triggered even when Open vSwitch is idle, making detection difficult. This vulnerability poses a significant risk to systems running affected kernel versions. The flaw was published on July 27, 2026, with the first proof of concept released shortly after on July 29. Organizations using Linux distributions with Open vSwitch are urged to assess their systems for this vulnerability.
Key Points: • OVSwrap (CVE-2026-64531) allows local users to escalate privileges to root on Linux systems. • A public exploit exists, impacting around 800 x86-64 kernel builds, raising detection concerns. • The vulnerability was disclosed on July 27, 2026, with a CVSS score of 7.8, indicating high severity.