techjacksolutions.com • 4h
Linux Kernel ARM64 KVM VHE Flaw Enables Guest Host Memory Read/Write
A race condition in the ARM64 KVM virtualization host extensions (VHE) path allows a guest VM to retain access to freed host memory when nested virtualization is enabled, leading to arbitrary host kernel memory read/write. The flaw, tracked as CVE-2026-89775 (CVSS 9.8), can be chained via the ITScape exploit to achieve full guest‑to‑host escape and root‑level code execution on the host. Affected systems include any Linux kernel on ARM64 with KVM VHE and nested virt enabled, notably RHEL 8.4 EUS and its derivatives. Immediate mitigation requires applying the upstream kernel patch or disabling nested virtualization.