Linux Kernel Flaw Lets Local Users Seize Full Control of Systems
Security researchers have disclosed a serious flaw in the Linux kernel's Open vSwitch networking component, tracked as CVE-2026-64531 and nicknamed 'OVSwrap'. The vulnerability, rated 7.8 out of 10 in severity, is a memory corruption bug that allows a local user with limited privileges to escalate to full root access on many default-configured Linux systems.
What makes this flaw particularly concerning for businesses running Linux servers is that a public exploit already exists, complete with pre-built configurations covering roughly 800 different kernel builds. This significantly lowers the technical bar for exploitation, meaning attackers don't need deep expertise to take advantage of it—they just need existing access to a vulnerable machine, such as through a compromised low-privilege account or malicious insider.
While the flaw requires local access rather than being remotely exploitable over the internet, this is not a strong protection in practice. Attackers often gain initial low-level access through phishing, stolen credentials, or other footholds, then use flaws like this one to gain complete control of a system. Businesses running Linux-based servers, cloud instances, or network infrastructure using Open vSwitch should treat this as a priority patching issue.