logo

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

ID: 560216da-58ed-5349-8083-164e7719a3a9

STIX ID: report--560216da-58ed-5349-8083-164e7719a3a9

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

Author: [email protected] (The Hacker News)

ADMIRALTY:B6
...
...

Zapscape (CVE-2026-64561) is a KVM/x86 shadow-MMU stale-root use-after-free vulnerability that can allow an L1 guest with kernel (root) privileges to escape nested virtualization isolation and execute code on the host; a public proof-of-concept exists but no confirmed in-the-wild exploitation, and upstream patches have been merged with vendor advisories and fixed stable kernels available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.