New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
PoC publicOpen vSwitchOur summary
A new privilege escalation vulnerability affecting the Linux kernel's Open vSwitch component allows unprivileged local users to gain root access on many distributions. The flaw, named OVSwrap and assigned CVE-2026-64531, was disclosed by researcher Asim Manizada on July 28, 2026. A working proof-of-concept is now publicly available for around 800 kernel builds.
The issue resides in the kernel datapath of Open vSwitch and enables attackers to exploit a memory corruption bug without needing an active OVS bridge or administrative privileges. A patch has been included upstream since July 24, but distribution-specific updates may vary. Systems using Open vSwitch should either apply vendor patches or block the module from loading until fixes are available.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.