cybersecurity.pk • 2h
Critical KVM/Linux Vulnerability: Zapscape CVE-2026-64561 VM Escape
The Zapscape vulnerability (CVE-2026-64561) is a critical flaw in the KVM/x86 shadow Memory Management Unit (MMU) state management. During nested virtualization operations, a failure to correctly synchronize shadow page tables allows an attacker with kernel-level privileges in a Level 1 (L1) guest to manipulate memory mappings. This facilitates a virtual machine escape (VME), permitting arbitrary code execution on the host Linux kernel. The vulnerability compromises the hypervisor-guest isolation boundary, enabling full host takeover and lateral movement across co-resident virtual machines in multi-tenant environments. Immediate patching of KVM and the Linux kernel is required to mitigate this risk.