New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
AI Summary
A memory corruption vulnerability in the Linux kernel's Open vSwitch (OVS) datapath, tracked as CVE-2026-64531 and dubbed OVSwrap, allows local users to escalate privileges to root. The flaw stems from a 16-bit length field wraparound when processing Netlink attributes in OVS flow installation, which can be triggered without requiring existing OVS bridges or daemons. A public proof-of-concept exploit achieves reliable local privilege escalation by chaining kernel pointer leaks, arbitrary reads, and targeted decrements to modify credentials and gain root access. The exploit supports around 800 kernel builds and leaves behind modified sudoers files and persistent root shells. Default installations of numerous Linux distributions are vulnerable if Open vSwitch is enabled and unprivileged user namespaces are allowed.
AI-extracted · verify before operational use