Junglewise Threat Intelligence

CVE-2026-64531: Linux Kernel Open vSwitch length truncation in nested actions

CVE-2026-64531 · Severity: info · CVSS 0 · Published 2026-07-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Open vSwitch component could allow for improper processing of network traffic rules. Open vSwitch is a virtual switch used to manage network traffic between virtual machines and physical networks. An attacker could potentially bypass security validations or cause the system to misinterpret network actions, leading to unpredictable behavior or security policy violations.

Technical details

A vulnerability exists in 'net/openvswitch/flow_netlink.c' where nested Netlink attributes (nlattrs) can exceed the 16-bit length limit (U16_MAX) without being rejected. This occurs because a previous commit removed length checks for the total action stream, inadvertently allowing individual nested containers to grow beyond 64 KiB. When such a container is closed, its length field is truncated, causing subsequent bytes in the stream to be misinterpreted as independent actions during later dump or teardown operations. This can lead to a discrepancy between validated and executed flow actions, specifically affecting CLONE, CT, SAMPLE, and DEC_TTL actions. The fix introduces explicit checks in 'add_nested_action_end' to reject containers exceeding U16_MAX and ensures proper resource cleanup during failure.

Affected products

  • Linux Linux Kernel net/openvswitch/flow_netlink.c

Timeline

  • 2026-07-06: disclosed: Initial patch submitted by Asim Viladi Oglu Manizada
  • 2026-07-24: patched: Patch committed to stable tree by Greg Kroah-Hartman
  • 2026-07-27: advisory: CVE-2026-64531 published

References

Related threats