<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>OpenvSwitch | OKHK 👀</title><description>数字泔水\(⁠◔⁠‿⁠◔⁠)✨ Thinking...</description><link>https://tg.okhk.net</link><item><title>🔴 Linux 内核 Open vSwitch 模块本地提权漏洞 OVSwrap</title><link>https://tg.okhk.net/posts/10755</link><guid isPermaLink="true">https://tg.okhk.net/posts/10755</guid><pubDate>Fri, 07 Aug 2026 07:56:17 GMT</pubDate><content:encoded>&lt;div class=&quot;tgme_widget_message_forwarded_from accent_color&quot;&gt;Forwarded from &lt;a class=&quot;tgme_widget_message_forwarded_from_name&quot; href=&quot;https://t.me/outvivid/4896&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;&lt;span&gt;层叠 - The Cascading&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;i class=&quot;emoji&quot;&gt;&lt;b&gt;🔴&lt;/b&gt;&lt;/i&gt; Linux 内核 Open vSwitch 模块本地提权漏洞 OVSwrap。&lt;br /&gt;&lt;br /&gt;- 在用户命名空间有 CAP_NET_ADMIN 权限的进程 (&lt;code&gt;unshare -Urn&lt;/code&gt;) 即可以利用此漏洞提权。&lt;br /&gt;- 大多主流发行版均受到影响。&lt;br /&gt;- Mitigation 是禁用 &lt;code&gt;&lt;mark class=&quot;highlight&quot;&gt;openvswitch&lt;/mark&gt;&lt;/code&gt; 模块或 unprivileged user namespace 。&lt;br /&gt;- Kernel 上游和 Debian 各支持版本已经发布修复。&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://heyitsas.im/posts/ovswrap/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;heyitsas.im/~&quot;&gt;heyitsas.im/~&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;CVE: CVE-2026-64531&lt;br /&gt;CVSS: 7.8 (&lt;a href=&quot;http://kernel.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;kernel.org&quot;&gt;kernel.org&lt;/a&gt;)&lt;br /&gt;Fixed-In: 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, 7.1.5&lt;br /&gt;&lt;br /&gt;[感谢一位匿名订户提供信息。]&lt;br /&gt;&lt;br /&gt;&lt;i&gt;EDIT 8/7&lt;/i&gt;: 修正对利用此漏洞条件的描述。&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;/search/result?q=%23OpenvSwitch&quot; title=&quot;#OpenvSwitch&quot;&gt;#OpenvSwitch&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23Kernel&quot; title=&quot;#Kernel&quot;&gt;#Kernel&lt;/a&gt;</content:encoded></item></channel></rss>