← Back to Feed

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

CVE-2026-64561

August 6, 2026 · The Hacker News · Severity: HIGH

Zapscape , a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as  CVE-2026-64561  and affects KVM/x86's shadow memory management unit (MMU), which manages shadow page tables used for nested guest memory translation. Security researcher Hyunwoo Kim, who disclosed the bug, said the demonstrated exploit path can run commands on the host with kernel, or root, privileges.

Zapscape , a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86's shadow memory management unit (MMU), which manages shadow page tables used for nested guest memory translation. Security researcher Hyunwoo Kim, who disclosed the bug, said the demonstrated exploit path can run commands on the host with kernel, or root, privileges. The upstream fix has been merged, and administrators running KVM hosts that expose nested virtualization to untrusted guests should update to a fixed stable kernel or a vendor package that backports the patch. The required L1 kernel privilege usually means guest root. Intel systems also require both EPT page-walk length 4 and 5 to be exposed to the L1 guest. AMD has no equivalent condition.

Key Takeaways

  • A new KVM vulnerability (CVE-2026-64561) allows a privileged L1 guest to escape to the host system through a flaw in KVM's interrupt handling.
  • The Zapscape flaw affects systems running KVM with specific hardware configurations, impacting cloud providers and virtualized environments.
  • Red Hat has issued security guidance and kernel patches are available for affected distributions.
☕ Buy a Coffee