CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-64531: OVSwrap Linux Kernel Flaw

August 5, 2026

A memory corruption vulnerability in the Linux kernel's Open vSwitch datapath allows local users to gain root privileges. The flaw involves a 16-bit length field wrap in Netlink attributes, leading to memory corruption. Exploitation requires unprivileged user namespaces and OVS conntrack support. Fixed in Linux stable releases 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5.