CVE Tools
Back to feed
PoC public Open vSwitch ics-ot-iot Linux Kernel privilege-escalation

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

The Hacker News·By The Hacker News··4 min read
CVE Tools coverage

A new privilege escalation vulnerability affecting the Linux kernel's Open vSwitch component allows unprivileged local users to gain root access on many distributions. The flaw, named OVSwrap and assigned CVE-2026-64531, was disclosed by researcher Asim Manizada on July 28, 2026. A working proof-of-concept is now publicly available for around 800 kernel builds.

The issue resides in the kernel datapath of Open vSwitch and enables attackers to exploit a memory corruption bug without needing an active OVS bridge or administrative privileges. A patch has been included upstream since July 24, but distribution-specific updates may vary. Systems using Open vSwitch should either apply vendor patches or block the module from loading until fixes are available.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store