Linux Kernel Vulnerability in Open vSwitch Related to Nested Action Attributes
CVE-2026-64531

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-64531?

A vulnerability in Open vSwitch allows for oversized nested action attributes which can disrupt the intended processing of generated actions. This occurs when the total size of flow actions exceeds 64 KiB due to a recent modification that lifted previous restrictions. If an oversized action is not properly validated, it can lead to a structural misalignment of the action stream, enabling potentially malicious interpretations of subsequent actions. This could result in unpredictable behavior or exploitation opportunities within the network. It is essential to mitigate this issue through validation checks for nested action closures, ensuring that generated actions conform to expected size limits.

Affected Version(s)

Linux 057dbc5b72e9fcac439cd561c3a539b8a0edeb92

Linux 2532adbfe917c0e71dba2650ffc6efe396314c87

Linux 4b1a0ee6164c7204c68ab5a9c48c07bfe8852485

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.