vulnerability
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
High
Summary
A vulnerability (CVE-2026-64561) in the KVM virtualization software allows a privileged guest user to potentially escape the virtualization environment and execute code on the host system. This stems from a stale-root check ordering flaw within KVM's shadow memory management unit (MMU). The issue requires nested virtualization exposed to untrusted guests and specific hardware configurations (Intel EPT page-walk length 4 and 5, AMD no equivalent).
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
