New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
AI Summary
A new Linux kernel vulnerability in KVM's shadow memory management unit, tracked as CVE-2026-64561 and dubbed 'Zapscape', enables a privileged attacker within an L1 guest VM to escape to the host system when nested virtualization is exposed. The flaw stems from a stale-root check ordering issue leading to a use-after-free condition during page fault handling, allowing post-free writes and potential host code execution. A public proof-of-concept demonstrates the ability to create a file on the host with root privileges, though the exploit requires adaptation for real-world use. The vulnerability affects Linux versions from 5.9 until fixed versions, with upstream patches merged and assigned CVE-2026-64561.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | /Zapscape | Details → |