ITScape KVM Escape: Public PoC Exploit Threatens Cloud Hosts
ID: 28d483c4-a41f-5d84-828e-d73296802da8
STIX ID: report--28d483c4-a41f-5d84-828e-d73296802da8
Feed Name: securityonline.info
Threat Score
A critical KVM/arm64 vulnerability (CVE-2026-46316, dubbed ITScape) and a public proof-of-concept exploit have been disclosed; the flaw is a VGIC-ITS race condition allowing untrusted guest VMs to escape to the host and obtain kernel (root) privileges, posing severe risk to multi-tenant arm64 public clouds — maintainers have merged a patch and operators must apply it immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
