#10
The Hacker News
general
August 06, 2026 at 17:58 UTC
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
By [email protected] (The Hacker News)
AI Summary
CVE-2026-64561, dubbed Zapscape, is a new Linux kernel vulnerability in KVM/x86's shadow MMU that allows an attacker with kernel privileges inside an L1 guest VM to escape KVM isolation and execute code on the host when nested virtualization is exposed to untrusted guests. The flaw is particularly relevant to cloud and virtualization providers where untrusted workloads run in nested VM configurations.
Relevance score: 73.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →