Our takeLocal root via Open vSwitch: CVE-2026-64531 is memory corruption in the OVS datapath, and the public exploit ships prebuilt for ~800 kernel builds. If a box loads the openvswitch module — virtualization and container hosts, mostly — patch kernels now; blacklist the module where unused.Cyber Resilience desk
Sources (2)
- hackernews · hackernews
- securityweek · securityweek
What this means for you — Security leader:Patch Linux kernels that ship the Open vSwitch datapath module (most default Ubuntu, Debian, RHEL, and SUSE builds). A public exploit already exists for roughly 800 kernel versions; apply vendor updates promptly and consider disabling the module on systems that do not require it.
What this means for you — Lean IT orgs:If you run Linux servers or desktops, check whether Open vSwitch is installed and update your kernel as soon as your distro releases the fix. Most small teams can simply run the normal system updates; servers without Open vSwitch are not affected.
What this means for you — MSP:Audit client Linux fleets for Open vSwitch usage, then prioritize kernel patching on any system with the vulnerable datapath module. Public exploits are already circulating; schedule updates in the next maintenance window for affected distributions.
What this means for you — Researcher:CVE-2026-64531 is a memory corruption flaw in the Linux kernel's Open vSwitch datapath that lets local users escalate to root; a working exploit with pre-built records for ~800 kernels is public.