linux-oracle vulnerability (CVE-2026-64531)
A security issue was discovered in the Linux kernel. An attacker could possibly use this to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch;
AI Analysis
Technical Summary
The Linux kernel's Open vSwitch stores generated flow actions as netlink attributes with a 16-bit length field (nla_len). A prior commit removed a length check that prevented nested action attributes from exceeding the maximum 16-bit length, allowing oversized nested containers with truncated length fields. This discrepancy causes later processing to interpret the action stream differently than originally validated, particularly with nested CLONE/CT actions, potentially leading to memory misinterpretation or corruption. The patch restores validation by rejecting oversized nested containers and ensures proper resource release during recursive action construction failures.
Potential Impact
This vulnerability allows an attacker with local privileges to craft malformed nested action attributes that bypass length validation, causing the kernel to process structurally different data streams. This can lead to memory corruption or unintended behavior affecting confidentiality, integrity, and availability of the system. The CVSS score of 7.8 reflects high impact with local attack vector and low complexity but requiring privileges.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to reject oversized nested action attributes in Open vSwitch and to properly release resources on failure. Users should apply the official kernel updates containing this patch. Since no patch links are provided here, check the Linux kernel vendor advisories or trusted sources for the updated kernel versions containing this fix. No alternative mitigations are indicated.
linux-oracle vulnerability (CVE-2026-64531)
Description
A security issue was discovered in the Linux kernel. An attacker could possibly use this to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch;
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel's Open vSwitch stores generated flow actions as netlink attributes with a 16-bit length field (nla_len). A prior commit removed a length check that prevented nested action attributes from exceeding the maximum 16-bit length, allowing oversized nested containers with truncated length fields. This discrepancy causes later processing to interpret the action stream differently than originally validated, particularly with nested CLONE/CT actions, potentially leading to memory misinterpretation or corruption. The patch restores validation by rejecting oversized nested containers and ensures proper resource release during recursive action construction failures.
Potential Impact
This vulnerability allows an attacker with local privileges to craft malformed nested action attributes that bypass length validation, causing the kernel to process structurally different data streams. This can lead to memory corruption or unintended behavior affecting confidentiality, integrity, and availability of the system. The CVSS score of 7.8 reflects high impact with local attack vector and low complexity but requiring privileges.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to reject oversized nested action attributes in Open vSwitch and to properly release resources on failure. Users should apply the official kernel updates containing this patch. Since no patch links are provided here, check the Linux kernel vendor advisories or trusted sources for the updated kernel versions containing this fix. No alternative mitigations are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-4pwv-pmm4-fw4r
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64531"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a6b72d09c2644c7f8476db3
Added to database: 07/30/2026, 15:50:40 UTC
Last enriched: 08/22/2026, 14:17:28 UTC
Last updated: 09/14/2026, 22:01:36 UTC
Views: 57
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.