importantSYS.SOURCE: The Hacker News• 2026-09-22T17:08:40+05:30
Critical Linux Kernel Vulnerability Allows ARM64 KVM Guests to Access Host Memory
A critical Linux kernel vulnerability (CVE-2026-89775) allows ARM64 KVM guests to gain read-write access to host memory when nested virtualization is enabled. The flaw is fixed in Linux 6.18.51, 7.2.5, and 7.3-rc1, but remains unpatched in older distributions and cloud environments.
A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled.
The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.
*** END OF TRANSMISSION ***