news.mlab.sh
Back to the feed
vulnerability

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

High
Image: The Hacker News
Summary

A vulnerability (CVE-2026-64561) in the KVM virtualization software allows a privileged guest user to potentially escape the virtualization environment and execute code on the host system. This stems from a stale-root check ordering flaw within KVM's shadow memory management unit (MMU). The issue requires nested virtualization exposed to untrusted guests and specific hardware configurations (Intel EPT page-walk length 4 and 5, AMD no equivalent).

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.