Home / Aug 08, 2026 / Story
0
#10 The Hacker News general August 06, 2026 at 17:58 UTC

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

By [email protected] (The Hacker News)

AI Summary

CVE-2026-64561, dubbed Zapscape, is a new Linux kernel vulnerability in KVM/x86's shadow MMU that allows an attacker with kernel privileges inside an L1 guest VM to escape KVM isolation and execute code on the host when nested virtualization is exposed to untrusted guests. The flaw is particularly relevant to cloud and virtualization providers where untrusted workloads run in nested VM configurations.

Relevance score: 73.0/100

# More from August 08