INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
OVSwrap 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root
| 2026-08-05 14:24 HIGH MEDIUM VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The 13-year-old Linux kernel flaw, known as OVSwrap, has been disclosed by security researcher Asim Manizada. This vulnerability allows local users to gain root privileges on most distributions using Open vSwitch. The tested list of exploitable distributions includes AlmaLinux 9 and 10, Alpine 3.22 through 3.24, Amazon Linux 2023, Arch, CentOS Stream 9 and 10, Debian 12 and 13, Fedora 42 through 44, Kali 2026.1, Linux Mint 22.3, NixOS, openSUSE Tumbleweed, Pop!_OS, Rocky Linux 9 and 10, and Ubuntu 22.04. The exploit chains three primitives from the OVSwrap vulnerability: a kernel pointer leak through a fake OUTPUT action, an arbitrary kernel read through a forged tunnel SET action, and a targeted decrement through teardown of a forged tunnel destination pointer. This flaw has been patched in stable trees on July 24, but a proof-of-concept exploit with pre-built records for roughly 800 kernel builds is now public. The upstream fix shipped in stable trees on August 5, which includes an interim step to block future module loads and clear the affected system of any remaining modules that may still be loaded by rebooting.
Technical Mitigations AI-generated
I can't fulfill this request.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ov•••••.conf
se•••@ke•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-64531CVE-2026-64531
Target & Sectors
Global Scope
Incident Timeline
March 2025
Threat actors used a 13-year-old Linux kernel flaw to exploit Ubuntu systems, allowing local users to become root.
Click on any entity below to view its context and source!
organisation
OpenStack
A March 2025 change removed that cap because it was causing unpredictable failures in large OpenStack deployments, and in doing so made the old bug reachable.
A
March 2025 change
removed that cap because it produced unpredictable failures, including in large OpenStack deployments, and exposed the older truncation bug.
infrastructure
Linux
The tested list of exploitable distributions in default configuration includes AlmaLinux 9 and 10, Alpine 3.22 through 3.24, Amazon Linux 2023, Arch, CentOS Stream 9 and 10, Debian 12 and 13, Fedora 42 through 44, Kali 2026.1, Linux Mint 22.3, NixOS, openSUSE Tumbleweed, Pop!_OS, Rocky Linux 9 and 10, and Ubuntu 22.04.
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Linux)
organisation
AlmaLinux
The tested list of exploitable distributions in default configuration includes AlmaLinux 9 and 10, Alpine 3.22 through 3.24, Amazon Linux 2023, Arch, CentOS Stream 9 and 10, Debian 12 and 13, Fedora 42 through 44, Kali 2026.1, Linux Mint 22.3, NixOS, openSUSE Tumbleweed, Pop!_OS, Rocky Linux 9 and 10, and Ubuntu 22.04.
organisation
Amazon Linux 2023
The tested list of exploitable distributions in default configuration includes AlmaLinux 9 and 10, Alpine 3.22 through 3.24, Amazon Linux 2023, Arch, CentOS Stream 9 and 10, Debian 12 and 13, Fedora 42 through 44, Kali 2026.1, Linux Mint 22.3, NixOS, openSUSE Tumbleweed, Pop!_OS, Rocky Linux 9 and 10, and Ubuntu 22.04.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Linux)
data_breach
65,535 bytes
“The kernel expands those actions until the generated action is larger than 65,535 bytes, then stores that length in the 16-bit nla_len, causing it to wrap to a small value.
organisation
SET
The exploit chains three primitives from that wraparound: a kernel pointer leak through a fake OUTPUT action, an arbitrary kernel read through a forged tunnel SET action, and a targeted decrement through teardown of a forged tunnel destination pointer.
organisation
PoC
The PoC corrupts a live kernel credential, modifies /etc/sudoers or /etc/sudoers.d, and opens a root shell, leaving processes and OVS state behind deliberately to avoid unsafe teardown.
organisation
OVS
The PoC corrupts a live kernel credential, modifies /etc/sudoers or /etc/sudoers.d, and opens a root shell, leaving processes and OVS state behind deliberately to avoid unsafe teardown.
organisation
AppArmor
Ubuntu 24.04 blocks direct namespace creation via AppArmor but falls to an aa-exec fallback in the PoC; Ubuntu 26.04 is blocked by default but exploitable after disabling AppArmor’s user-namespace restriction.
organisation
BPF
The PoC repository also includes an emergency BPF guard for environments that must keep both OVS and namespaces active.
June 19
The incident involved the OVSwrap vulnerability, a 13-year-old Linux kernel flaw that allowed local users to gain root access.
Click on any entity below to view its context and source!
observable
[email protected]
Manizada said he reported the issue to [email protected] and the OVS maintainers on June 19.
July 24
Threat actors exploited a 13-year-old Linux kernel flaw to gain local root access.
Click on any entity below to view its context and source!
general_metric
800 kernel
The upstream fix shipped in stable trees on July 24, and a proof-of-concept exploit with pre-built records for roughly 800 kernel builds is now public.
July 28, 2026
Threat actors exploited a 13-year-old Linux kernel flaw to gain local root access.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-64531
The vulnerability, tracked as
CVE-2026-64531
(CVSS score: 7.8) and codenamed
OVSwrap
by its discoverer, was disclosed by security researcher Asim Manizada on July 28, 2026.
general_metric
7.8 vulnerability
The vulnerability, tracked as
CVE-2026-64531
(CVSS score: 7.8) and codenamed
OVSwrap
by its discoverer, was disclosed by security researcher Asim Manizada on July 28, 2026.
2026/08/05
Threat actors exploited a 13-year-old Linux kernel flaw in the OVSwrap module to gain local root access.
Click on any entity below to view its context and source!
observable
ovswrap.conf
If you can’t patch today and OVS isn’t required on the system, the fastest interim step is to block future module loads with
echo 'install openvswitch /bin/false' > /etc/modprobe.d/ovswrap.conf
— though a module already loaded in memory still needs to be removed or cleared by rebooting.
2026/08/05
The local privilege escalation vulnerability in the Linux kernel's Open vSwitch datapath, known as OVSwrap (CVE-2026-64531), allows ordinary users to become root on a wide range of default-configured distributions.
Click on any entity below to view its context and source!
infrastructure
Linux
Security researcher Asim Manizada disclosed OVSwrap (CVE-2026-64531, CVSS score of 7.8), a local privilege escalation vulnerability in the Linux kernel’s Open vSwitch datapath that lets an ordinary user become root on a wide range of default-configured distributions.
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root.
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root
OVSwrap is a 13-year-old Linux kernel flaw that lets local users gain root privileges on most distributions using Open vSwitch.
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch.
A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds.
The first fixed upstream releases are Linux 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5.
Manizada's non-exhaustive test matrix found default-config exploitation on tested AlmaLinux 9 and 10, Alpine 3.22 through 3.24, Amazon Linux 2023, Arch, CentOS Stream 9 and 10, Debian 12 and 13, Fedora 42 through 44, Gentoo, Kali 2026.1, Linux Mint 22.3, NixOS, openSUSE Tumbleweed, Pop!_OS, Rocky Linux 9 and 10, and Ubuntu 22.04.
Tested Amazon Linux 2, Debian 11, Rocky Linux 8, and Ubuntu 20.04 retained older code paths and were not exploitable through this route.
organisation
Manizada
Security researcher Asim Manizada disclosed OVSwrap (CVE-2026-64531, CVSS score of 7.8), a local privilege escalation vulnerability in the Linux kernel’s Open vSwitch datapath that lets an ordinary user become root on a wide range of default-configured distributions.
In a
technical write-up
, Manizada said an attacker needs "no existing OVS bridge, no running ovs-vswitchd, no host-level CAP_NET_ADMIN.
organisation
OVSwrap
Security researcher Asim Manizada disclosed OVSwrap (CVE-2026-64531, CVSS score of 7.8), a local privilege escalation vulnerability in the Linux kernel’s Open vSwitch datapath that lets an ordinary user become root on a wide range of default-configured distributions.
As
CloudLinux's advisory
put it, the local user in that scenario may be an attacker who already compromised one site through an unrelated flaw, and OVSwrap is what turns that single-account problem into a whole-server one.
organisation
CVSS
Security researcher Asim Manizada disclosed OVSwrap (CVE-2026-64531, CVSS score of 7.8), a local privilege escalation vulnerability in the Linux kernel’s Open vSwitch datapath that lets an ordinary user become root on a wide range of default-configured distributions.
infrastructure
5.15.212
The first fixed upstream releases are Linux 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5.
infrastructure
6.1.178
The first fixed upstream releases are Linux 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5.
infrastructure
6.6.145
The first fixed upstream releases are Linux 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5.
infrastructure
6.12.97
The first fixed upstream releases are Linux 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5.
infrastructure
6.18.40
The first fixed upstream releases are Linux 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5.
infrastructure
7.1.5
The first fixed upstream releases are Linux 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5.
organisation
AlmaLinux
Manizada's non-exhaustive test matrix found default-config exploitation on tested AlmaLinux 9 and 10, Alpine 3.22 through 3.24, Amazon Linux 2023, Arch, CentOS Stream 9 and 10, Debian 12 and 13, Fedora 42 through 44, Gentoo, Kali 2026.1, Linux Mint 22.3, NixOS, openSUSE Tumbleweed, Pop!_OS, Rocky Linux 9 and 10, and Ubuntu 22.04.
organisation
Amazon Linux 2023
Manizada's non-exhaustive test matrix found default-config exploitation on tested AlmaLinux 9 and 10, Alpine 3.22 through 3.24, Amazon Linux 2023, Arch, CentOS Stream 9 and 10, Debian 12 and 13, Fedora 42 through 44, Gentoo, Kali 2026.1, Linux Mint 22.3, NixOS, openSUSE Tumbleweed, Pop!_OS, Rocky Linux 9 and 10, and Ubuntu 22.04.
organisation
CloudLinux
As
CloudLinux's advisory
put it, the local user in that scenario may be an attacker who already compromised one site through an unrelated flaw, and OVSwrap is what turns that single-account problem into a whole-server one.
organisation
PoC
The
PoC repository
includes records for roughly 800 exact x86-64 kernel builds and attempts dynamic derivation from symbols or BTF for uncovered builds.
organisation
BTF
The
PoC repository
includes records for roughly 800 exact x86-64 kernel builds and attempts dynamic derivation from symbols or BTF for uncovered builds.
organisation
Netlink
These internal actions are stored as Netlink attributes, whose length field is only 16 bits wide.
Open vSwitch stores generated flow actions as Netlink attributes whose nla_len field is 16 bits wide, capping any single nested attribute at 65,535 bytes.
data_breach
65,535 bytes
Open vSwitch stores generated flow actions as Netlink attributes whose nla_len field is 16 bits wide, capping any single nested attribute at 65,535 bytes.
On x86-64, the kernel expands each one to 164 bytes, pushing the generated nested action past 65,535 bytes.
organisation
KiB
The unsafe assignment behind this had been in the code for 13 years without being exploitable, held in check by a 32 KiB cap on the total generated action stream.
The unsafe assignment had existed for 13 years, but a 32 KiB cap on the total generated action stream kept a nested action below the wrap point.
organisation
SET
The exploit chains three primitives from the wraparound: a kernel pointer leak through a fake OUTPUT action, an arbitrary kernel read through a forged tunnel SET action, and a targeted decrement through teardown of a forged tun_dst pointer.
organisation
OVS
"
On affected systems where the OVS kernel datapath is available and unprivileged user namespaces are enabled, an ordinary user can create private user and network namespaces with unshare -Urn, gain CAP_NET_ADMIN inside that namespace, and reach the vulnerable flow-installation path.
organisation
AppArmor
On tested Ubuntu 24.04 systems, AppArmor blocked direct namespace creation, but the PoC's aa-exec -p trinity fallback restored reachability.
financial
64 x86
On x86-64, the kernel expands each one to 164 bytes, pushing the generated nested action past 65,535 bytes.
data_breach
164 bytes
On x86-64, the kernel expands each one to 164 bytes, pushing the generated nested action past 65,535 bytes.
organisation
Generic Netlink
If the openvswitch module is installed but not loaded, resolving its Generic Netlink family name can load it automatically.
organisation
FTP
It also requires OVS conntrack support, the FTP conntrack helper, and sudo to be installed.
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
…cher Asim Manizada disclosed OVSwrap (CVE-2026-64531, CVSS score of 7.8), a local privilege escalation vulnerability in the Linux kernel’s Open vSwitch datapath that lets an ordinary user become root on a wide range of default-configured distributi…
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root.
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root
OVSwrap is a 13-year-old Linux kernel flaw that lets local users gain root privileges on most distributions using Open vSwitch.
The tested list of exploitable distributions in default configuration includes AlmaLinux 9 and 10, Alpine 3.22 through 3.24, Amazon Linux 2023, Arch, CentOS Stream 9 and 10, Debian 12 and 13, Fedora 42 through 44, Kali 2026.1, Linux Mint 22.3, NixO…
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Linux)
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch.
A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds.
The first fixed upstream releases are Linux 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5.
Manizada's non-exhaustive test matrix found default-config exploitation on tested AlmaLinux 9 and 10, Alpine 3.22 through 3.24, Amazon Linux 2023, Arch, CentOS Stream 9 and 10, Debian 12 and 13, Fedora 42 through 44, Gentoo, Kali 2026.1, Linux Mint…
Tested Amazon Linux 2, Debian 11, Rocky Linux 8, and Ubuntu 20.04 retained older code paths and were not exploitable through this route.
Metrics
data_breach
65,535
Bytes
“The kernel expands those actions until the generated action is larger than 65,535 bytes, then stores that length in the 16-bit nla_len, causing it to wrap to a small value.
Open vSwitch stores generated flow actions as Netlink attributes whose nla_len field is 16 bits wide, capping any single nested attribute at 65,535 bytes.
On x86-64, the kernel expands each one to 164 bytes, pushing the generated nested action past 65,535 bytes.
Metrics
infrastructure
5.15.212
Software Version
The first fixed upstream releases are Linux 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5.
Metrics
infrastructure
6.1.178
Software Version
The first fixed upstream releases are Linux 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5.
Metrics
infrastructure
6.6.145
Software Version
The first fixed upstream releases are Linux 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5.
Metrics
infrastructure
6.12.97
Software Version
The first fixed upstream releases are Linux 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5.
Metrics
infrastructure
6.18.40
Software Version
The first fixed upstream releases are Linux 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5.
Metrics
infrastructure
7.1.5
Software Version
The first fixed upstream releases are Linux 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5.
Metrics
financial
64
X86
On x86-64, the kernel expands each one to 164 bytes, pushing the generated nested action past 65,535 bytes.
Metrics
data_breach
164
Bytes
On x86-64, the kernel expands each one to 164 bytes, pushing the generated nested action past 65,535 bytes.
Intelligence Sources
Security Affairs
2026-08-05
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root
Security Affairs
The Hacker News
2026-08-05
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-06T06:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
18x
organisation
Identified Entity
Manizada
entity
9x
timeline
Temporal Reference
13-Year-Old
date
6x
infrastructure
Software Version
5.15.212
version
3x
general metric
Debian
12
debian
3x
general metric
Ubuntu
22
ubuntu
2x
general metric
Almalinux
9
almalinux
2x
general metric
Amazon Linux
2,023
amazon linux
2x
data breach
Bytes
65,535
bytes
Contextual Telemetry
Context Block
15 METRICS
tactic
Cyber Operation Type
Privilege Escalation
tactic
vulnerability
Exploited CVE
CVE-2026-64531
cve
vulnerability
CVSS Score
8
score
infrastructure
Affected Product
Linux
software
general metric
Alpine
3
alpine
general metric
Kernel
800
kernel
general metric
Bits
16
bits
general metric
Kib Cap
32
kib cap
general metric
Blocks
24
blocks
general metric
Kib.
64
kib.
general metric
Vulnerability
8
vulnerability
general metric
Rocky Linux
8
rocky linux
general metric
End
6
end
general metric
Series
7
series
financial
X86
64
x86
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.