ZDI-26-687: Linux Kernel Open vSwitch Flow Delete Use-After-Free Information Disclosure Vulnerability
Published Sep 14, 2026
·Updated
This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-80994.
Affected Software
1 affected component
Linux Linux kernel
Event History
Sep 14, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
Is remote access sufficient to exploit this issue?
The available information describes this as a local vulnerability. An attacker must be able to execute low-privileged code on the affected system before exploitation is possible.
2
What identifier should be used to track this vulnerability?
This issue is assigned CVE-2026-80994. ZDI assigned it a CVSS score of 6.4.