Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-89775
CVE
CVE-2026-89775
View on NVD ↗
KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation
MITRE ATT&CK TTPs
2
T1055
Process Injection
Defense Evasion
T1068
Exploitation for Privilege Escalation
Privilege Escalation
Source Articles
New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
A vulnerability in the Linux kernel's KVM virtualization code for ARM64 processors, tracked as CVE-2026-89775, allows a guest virtual machine to read and write host kernel memory, potentially enabling guest-to-host escape. The flaw affects systems with nested virtualization enabled and stems from a missed TLB invalidation due to a zero-size calculation when handling guest memory. It impacts Linux kernels starting from version 6.17 and has been patched in 6.18.51, 7.2.5, and 7.3-rc1. While no active exploitation has been observed, local users on vulnerable systems—such as those with /dev/kvm accessible—could exploit it to escalate privileges to root.
hacker-news
Sep 22, 2026