Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Linux Kernel Vulnerability Allows Root Access via OVSwrap

Linux Kernel Vulnerability Allows Root Access via OVSwrap

Posted on August 5, 2026 By CWS

A critical flaw in the Linux kernel’s Open vSwitch component could enable local users to escalate privileges to root on numerous default-configured distributions. This vulnerability, identified as CVE-2026-64531 and named OVSwrap, was disclosed by security researcher Asim Manizada on July 28, 2026.

Details of the Vulnerability

The flaw resides within the kernel datapath rather than the userspace ovs-vswitchd daemon. Manizada’s technical analysis reveals that attackers do not require an existing OVS bridge, a running ovs-vswitchd, or host-level CAP_NET_ADMIN privileges to exploit this vulnerability. On systems where the OVS kernel datapath is accessible and unprivileged user namespaces are active, users can create private user and network namespaces, gaining CAP_NET_ADMIN and accessing the vulnerable flow-installation path.

Even if the openvswitch module is not loaded, querying its Generic Netlink family name can trigger its automatic loading, leaving systems vulnerable unless the module is explicitly blocked. A fix has been provided in stable kernel releases since July 24.

Exploitation and Impact

The flaw, which results from a memory corruption issue, has been present for over a decade due to unsafe assignments in OVS. Actions stored as Netlink attributes have a length field that can overflow, allowing attackers to create an exploit chain using kernel pointer leaks, arbitrary reads, and targeted decrements. This can ultimately lead to unauthorized root access.

The proof-of-concept exploit requires specific conditions, such as installed OVS conntrack support and sudo. Upon successful exploitation, it modifies critical system files like /etc/sudoers to open a root shell, leaving behind processes to prevent unsafe teardown.

Mitigation Measures

System administrators are advised to install patched vendor kernels as soon as they become available. In environments where Open vSwitch is not needed, blocking the module from loading provides an immediate safeguard. Disabling unprivileged user namespaces can also mitigate the risk but may not protect against processes with existing CAP_NET_ADMIN privileges.

The risk is heightened in shared host environments, where a compromised account can exploit OVSwrap to escalate privileges across the entire server. For environments that must maintain both OVS and namespaces, an emergency BPF guard is recommended.

To conclude, while the vulnerability is severe, prompt action in applying patches and adjusting configurations can significantly reduce the risk of exploitation. Security teams should remain vigilant and monitor vendor updates to ensure comprehensive protection against this and similar threats.

The Hacker News Tags:CVE-2026-64531, Exploitation, kernel vulnerability, Linux, Open vSwitch, OVSwrap, Patch, root access, security flaw, security update

Post navigation

Previous Post: CISA Raises Alert on Apache Tomcat Encryption Flaw
Next Post: Cyber Operations’ Expanding Influence in Global Conflicts

Related Posts

Malicious RubyGems Packages Threaten Developer Security Malicious RubyGems Packages Threaten Developer Security The Hacker News
Anatsa Android Banking Trojan Hits 90,000 Users with Fake PDF App on Google Play Anatsa Android Banking Trojan Hits 90,000 Users with Fake PDF App on Google Play The Hacker News
Critical Security Threats and Global Cyber Developments Critical Security Threats and Global Cyber Developments The Hacker News
Claude AI Exploited to Operate 100+ Fake Political Personas in Global Influence Campaign Claude AI Exploited to Operate 100+ Fake Political Personas in Global Influence Campaign The Hacker News
How Attackers Exploit Trusted Tools in Cybersecurity How Attackers Exploit Trusted Tools in Cybersecurity The Hacker News
Malicious Notepad++ Plugin Exploits in UAC-0099 Campaign Malicious Notepad++ Plugin Exploits in UAC-0099 Campaign The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark