CVE-2026-80994: Linux Kernel Open vSwitch Flow Delete Use‑After‑Free Information Disclosure Vulnerability
What It Is – A use‑after‑free flaw in the Linux kernel’s Open vSwitch implementation (sw_flow_mask handling) allows a local attacker who can run low‑privileged code to read kernel memory. The vulnerability can be chained with other bugs to achieve privilege escalation.
Exploitability – Local‑only; requires attacker code execution at low privilege. No public exploit code, but the CVSS 6.4 rating (AV:L/AC:H/PR:L) reflects moderate difficulty.
Affected Products – Linux kernel (all distributions that include the affected Open vSwitch code).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous patch‑management evidence – auditors expect proof that critical kernel updates are applied promptly.
- Highlights the importance of vulnerability‑management controls that map to multiple frameworks (e.g., NIST CSF, ISO 27001) through a single control objective.
- Provides a concrete data point for defensible audit trails: documenting the remediation timeline satisfies due‑diligence expectations of enterprise buyers.
Recommended Actions – Apply the upstream Linux kernel patch (commit 4e30317f…), verify the running kernel version, update your asset inventory, and capture patch‑deployment evidence for audit purposes. Source: Zero Day Initiative Advisory