news.mlab.sh
2 results
vulnerability

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

A vulnerability (CVE-2026-64561) in the KVM virtualization software allows a privileged guest user to potentially escape the virtualization environment and execute code on the host system. This stems from a stale-root check ordering flaw within KVM's shadow memory management unit (MMU). The issue requires nested virtua…

The Hacker News · Aug 6, 2026 High