Black & White Path
Aug 6, 2026 · Information Security
OVSwrap: A 13-Year-Old Linux Kernel Flaw That Lets Any Local User Escalate to Root
OVSwrap (CVE‑2026‑64531) is a memory‑corruption bug in the Open vSwitch kernel data‑path that has lingered for 13 years; a low‑privilege local user can trigger a length‑wrap overflow to leak pointers, read kernel memory, and decrement fsuid/fsgid to gain root across dozens of major Linux distributions, with a publicly released PoC covering ~800 x86‑64 kernel versions and detailed mitigation steps.
CVE-2026-64531Linux kernelOVSwrap
0 likes · 16 min read
