Linux Kernel Vulnerability in Open vSwitch Related to Nested Action Attributes
CVE-2026-64531

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
27 July 2026

Badges

πŸ“ˆ TrendedπŸ“ˆ Score: 3,420πŸ‘Ύ Exploit Exists🟑 Public PoCπŸ“° News Worthy

What is CVE-2026-64531?

CVE-2026-64531 is a significant vulnerability related to the Open vSwitch component of the Linux kernel, which plays a crucial role in managing network traffic in virtualized environments. Open vSwitch is designed to provide network connectivity to virtual machines and containers, enabling dynamic and scalable network configurations. The vulnerability arises from an issue with the handling of nested action attributes in flow actions. Specifically, a change made in the kernel code allowed these action attributes to exceed their expected size limit, resulting in a scenario where improperly structured data could be processed. This mismanagement can lead to potential disruptions in the network configuration, unintended behavior, or other security risks, particularly affecting organizations that rely on robust virtual networking.

Potential Impact of CVE-2026-64531

  1. Network Disruptions: The vulnerability can cause malformed nested action attributes to lead to structural inconsistencies within the Open vSwitch's flow management. This can result in unexpected network behavior, potentially disrupting service availability for applications and users who depend on stable network configurations.

  2. Security Risks: The exploitation of this vulnerability could allow attackers to inject misleading flows into the virtual network's processing stream. This opens avenues for unauthorized access or control over network traffic, potentially allowing for data interception or manipulation by malicious actors.

  3. Resource Mismanagement: The vulnerability's nature involves improper handling of resource management, where forces nested attributes can lead to resource leaks or inefficiencies. Such scenarios can lead to increased demand on system resources, impacting overall performance and stability of both networking components and hosted applications.

Affected Version(s)

Linux 057dbc5b72e9fcac439cd561c3a539b8a0edeb92

Linux 2532adbfe917c0e71dba2650ffc6efe396314c87

Linux 4b1a0ee6164c7204c68ab5a9c48c07bfe8852485

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

New OVSwrap Linux Vulnerability Lets Attackers Gain Root Access

A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-64531 and dubbed OVSwrap, allows unprivileged local users to escalate privileges to root on a wide range of popular Linux distributions.

2 weeks ago

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

CVE-2026-64531 lets local users exploit Open vSwitch kernel memory corruption to gain root, with a public PoC covering roughly 800 builds.

2 weeks ago

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • πŸ“ˆ

    Vulnerability started trending

  • πŸ“°

    First article discovered by The Hacker News

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.