HomeIntelligenceBrief
VULNERABILITY BRIEF 🟡 Medium ThreatIntel

CVE-2026-80994: Linux Kernel Open vSwitch Flow Delete Use‑After‑Free Information Disclosure

A use‑after‑free bug in the Linux kernel’s Open vSwitch component (CVE‑2026‑80994) enables local attackers to read kernel memory and potentially escalate privileges. Enterprises must prove timely patching to satisfy audit and control‑assurance requirements.

Verisq™ Intelligence · 📅 September 14, 2026 · 📰 zerodayinitiative.com
🟡
Severity
Medium
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

CVE-2026-80994: Linux Kernel Open vSwitch Flow Delete Use‑After‑Free Information Disclosure Vulnerability

What It Is – A use‑after‑free flaw in the Linux kernel’s Open vSwitch implementation (sw_flow_mask handling) allows a local attacker who can run low‑privileged code to read kernel memory. The vulnerability can be chained with other bugs to achieve privilege escalation.

Exploitability – Local‑only; requires attacker code execution at low privilege. No public exploit code, but the CVSS 6.4 rating (AV:L/AC:H/PR:L) reflects moderate difficulty.

Affected Products – Linux kernel (all distributions that include the affected Open vSwitch code).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous patch‑management evidence – auditors expect proof that critical kernel updates are applied promptly.
  • Highlights the importance of vulnerability‑management controls that map to multiple frameworks (e.g., NIST CSF, ISO 27001) through a single control objective.
  • Provides a concrete data point for defensible audit trails: documenting the remediation timeline satisfies due‑diligence expectations of enterprise buyers.

Recommended Actions – Apply the upstream Linux kernel patch (commit 4e30317f…), verify the running kernel version, update your asset inventory, and capture patch‑deployment evidence for audit purposes. Source: Zero Day Initiative Advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-687/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →