A newly disclosed Linux kernel vulnerability, labeled as CVE-2026-64531 and known as OVSwrap, enables unprivileged local users to elevate privileges to root on various popular Linux distributions. This issue was identified by Asim Viladi Oglu Manizada through an experimental research approach that combines large language models with structured memory-geometry visualizations to analyze complex kernel memory bugs. However, previously, OVS failed to verify whether individual nested actions, such as those involving multiple small conntrack actions wrapped in CLONE, remained within this 16-bit limit.

Later kernel code assumes wrapped values and resumes parsing from an attacker-controlled data point, confusing parsers into treating forged data as legitimate actions.

An ordinary local user can create an unprivileged user and network namespace with commands like `unshare -Urn`, gain CAP_NET_ADMIN privileges within the isolated namespace, and spin up a private OVS datapath to reach the vulnerable code path. Security researchers identified a vulnerability in default configurations across various Linux distributions, including AlmaLinux, Debian, Fedora, Ubuntu, Rocky Linux, Arch Linux, openSUSE Tumbleweed, Amazon Linux, Kali Linux, NixOS, and Linux Mint. Administrators unable to patch immediately are advised to blacklist the openvswitch module if it is not needed, disable unprivileged user namespaces where feasible, or deploy the emergency BPF-based mitigation released alongside the proof-of-concept.

Enhance your Security Operations Center (SOC) by accelerating threat detection and swift investigations.