Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Linux Kernel Vulnerability Allows Root Access via OVSwrap

Linux Kernel Vulnerability Allows Root Access via OVSwrap

Posted on August 5, 2026 By CWS

A critical flaw in the Linux kernel’s Open vSwitch component could enable local users to escalate privileges to root on numerous default-configured distributions. This vulnerability, identified as CVE-2026-64531 and named OVSwrap, was disclosed by security researcher Asim Manizada on July 28, 2026.

Details of the Vulnerability

The flaw resides within the kernel datapath rather than the userspace ovs-vswitchd daemon. Manizada’s technical analysis reveals that attackers do not require an existing OVS bridge, a running ovs-vswitchd, or host-level CAP_NET_ADMIN privileges to exploit this vulnerability. On systems where the OVS kernel datapath is accessible and unprivileged user namespaces are active, users can create private user and network namespaces, gaining CAP_NET_ADMIN and accessing the vulnerable flow-installation path.

Even if the openvswitch module is not loaded, querying its Generic Netlink family name can trigger its automatic loading, leaving systems vulnerable unless the module is explicitly blocked. A fix has been provided in stable kernel releases since July 24.

Exploitation and Impact

The flaw, which results from a memory corruption issue, has been present for over a decade due to unsafe assignments in OVS. Actions stored as Netlink attributes have a length field that can overflow, allowing attackers to create an exploit chain using kernel pointer leaks, arbitrary reads, and targeted decrements. This can ultimately lead to unauthorized root access.

The proof-of-concept exploit requires specific conditions, such as installed OVS conntrack support and sudo. Upon successful exploitation, it modifies critical system files like /etc/sudoers to open a root shell, leaving behind processes to prevent unsafe teardown.

Mitigation Measures

System administrators are advised to install patched vendor kernels as soon as they become available. In environments where Open vSwitch is not needed, blocking the module from loading provides an immediate safeguard. Disabling unprivileged user namespaces can also mitigate the risk but may not protect against processes with existing CAP_NET_ADMIN privileges.

The risk is heightened in shared host environments, where a compromised account can exploit OVSwrap to escalate privileges across the entire server. For environments that must maintain both OVS and namespaces, an emergency BPF guard is recommended.

To conclude, while the vulnerability is severe, prompt action in applying patches and adjusting configurations can significantly reduce the risk of exploitation. Security teams should remain vigilant and monitor vendor updates to ensure comprehensive protection against this and similar threats.

The Hacker News Tags:CVE-2026-64531, Exploitation, kernel vulnerability, Linux, Open vSwitch, OVSwrap, Patch, root access, security flaw, security update

Post navigation

Previous Post: CISA Raises Alert on Apache Tomcat Encryption Flaw
Next Post: Cyber Operations’ Expanding Influence in Global Conflicts

Related Posts

Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery The Hacker News
EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations The Hacker News
Google Launches OSS Rebuild to Expose Malicious Code in Widely Used Open-Source Packages Google Launches OSS Rebuild to Expose Malicious Code in Widely Used Open-Source Packages The Hacker News
nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery The Hacker News
Chinese Hackers Weaponize Open-Source Nezha Tool in New Attack Wave Chinese Hackers Weaponize Open-Source Nezha Tool in New Attack Wave The Hacker News
Malicious Go Modules Deliver Disk-Wiping Linux Malware in Advanced Supply Chain Attack Malicious Go Modules Deliver Disk-Wiping Linux Malware in Advanced Supply Chain Attack The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cyber Operations’ Expanding Influence in Global Conflicts
  • Linux Kernel Vulnerability Allows Root Access via OVSwrap
  • CISA Raises Alert on Apache Tomcat Encryption Flaw
  • Data Breach Affects 311,000 at Brown Health Group
  • Gitea Vulnerability Allows File Access Without Authentication

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cyber Operations’ Expanding Influence in Global Conflicts
  • Linux Kernel Vulnerability Allows Root Access via OVSwrap
  • CISA Raises Alert on Apache Tomcat Encryption Flaw
  • Data Breach Affects 311,000 at Brown Health Group
  • Gitea Vulnerability Allows File Access Without Authentication

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark