importantSYS.SOURCE: The Hacker News• 2026-08-06T23:28:30+05:30
Critical KVM Vulnerability (CVE-2026-64561) Enables L1 Guest Code Escape to Linux Hosts
A critical KVM vulnerability (CVE-2026-64561) allows privileged L1 guests to escape to Linux hosts via a use-after-free flaw in the shadow-MMU. The issue affects Linux kernels 5.9 and later, with patches available, but unpatched systems remain at risk.
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests.
The flaw is tracked as CVE-2026-64561 and affects KVM/x86's shadow memory management unit (MMU), which manages shadow page
*** END OF TRANSMISSION ***