New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Read full story on The Hacker News
Share
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
AI disclosure

Summary

Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86's shadow memory management unit (MMU), which manages shadow page

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.