Crypto Ticker:
sysadmin from Cyber Security News

CVE-2026-64561 Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges

Abinaya
Aug 7, 2026 at 13:32
7 Views
0 Comments
CVE-2026-64561 Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges

A Linux kernel vulnerability, tracked as CVE-2026-64561 and named Zapscape, could allow attackers to escape a KVM virtual machine and take control of its underlying Linux host with root privileges. The issue affects KVM/x86, a virtualization technology that separates guest systems from the physical server. The flaw is especially serious for cloud providers and enterprises that run untrusted workloads. Zapscape was discovered by security researcher Hyunwoo Kim, known as V4bel. It exists in KVM’s shadow memory management unit, or shadow MMU. It manages memory translations when nested virtualization is used. Nested virtualization allows one virtual machine to run another virtual machine inside it. While useful for testing and...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!