ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Vulnerabilities

Zapscape KVM shadow MMU bug enables L1 guest escape to Linux hosts

Source headline: New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Threat level Critical
Signal strength 85/100
Source confidence 1 source
Published 2 hours ago

Intelligence Summary

A Linux kernel flaw dubbed Zapscape can let an attacker running with kernel privileges inside an L1 KVM guest escape the KVM isolation boundary. The issue targets KVM/x86 shadow memory management (MMU) used to emulate guest memory. Exploitation is most relevant when nested virtualization is enabled for untrusted L1 guests. If successful, the attacker could execute code on the underlying Linux host rather than staying confined to the VM. Systems using KVM with nested virtualization exposed to untrusted guests should review mitigations and patch status for CVE-2026-64561.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#cve #kvm #linux-kernel #nested-virtualization #privilege-escape
Original reporting The Hacker News New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Open original source