Zapscape (CVE-2026-64561) is another reminder that the hypervisor boundary is only as strong as the code implementing it.
The vulnerability is a guest-to-host escape in Linux KVM's x86 Shadow MMU. The root cause is a stale-root validation ordering bug that allows the page fault handler to continue using an invalidated shadow MMU root after quota reclaim, ultimately leading to a use-after-free primitive. Public research demonstrates a complete guest-to-host escape chain, although exploitation requires privileged code execution inside an L1 guest and nested virtualization exposure.
I put together a deep technical analysis covering the Shadow MMU internals, nested virtualization, exploitation stages, cross-cache reallocation, KASLR bypass, AMD vs. Intel trigger conditions, the upstream fix, and why simply moving a stale-root check eliminates the entire exploitation chain.
Interested to hear how others assess the practical risk for multi-tenant KVM deployments where nested virtualization is enabled.
https://thecybersecguru.com/news/zapscape-cve-2026-64561-kvm-guest-host-escape/
#Linux #KVM #Virtualization #KernelSecurity #CloudSecurity #CVE202664561
About This Hashtag
#kernelsecurity
4 posts
Last used Aug 07
#kernelsecurity
4 posts· Last used Aug 07
Linux kernel CVEs surged to 440 advisories in just 24 hours, with many flaws found by AI. Most are already patched, so update your kernel promptly.
#Linux #CVE #KernelSecurity #AI #CyberSecurity
https://securityonline.info/linux-kernel-cves/?utm_source=mastodon&utm_medium=jetpack_social
Three FreeBSD privilege escalation flaws, including a kernel use-after-free, let local users gain root. Patch FreeBSD 14 and 15 now.
#FreeBSD #PrivilegeEscalation #KernelSecurity #CyberSecurity #Vulnerability #InfoSec
http://securityonline.info/freebsd-privilege-escalation-flaws/?utm_source=mastodon&utm_medium=jetpack_social
A Linux kernel vulnerability (CVE-2024-26582) has a public PoC that turns a TLS use-after-free into a root shell. Details and exploit are out.
#Linux #KernelSecurity #CVE202426582 #UseAfterFree #CyberSecurity
https://securityonline.info/linux-kernel-cve-2024-26582-root-shell/?utm_source=mastodon&utm_medium=jetpack_social
You've seen all posts