Search
Find merged stories by title or summary.
Linux KVM/arm64 Vulnerability Lets Attackers Escape Virtual Machines and Gain Host Access
A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-89775, could let attackers escape an ARM64 virtual machine and access the underlying host system. The issue affects KVM/arm64 environments where nested virtualization is enabled, creating a serious risk for multi-tenant cloud infrastructure and systems that allow untrusted users to create virtual machines. Security researcher Hyunwoo Kim reported that the flaw stems from a type truncation issue in the KVM/arm64 stage-1 page-table walk process. The bug affects how the kernel calculates the size of a memory region it must invalidate from the virtual CPU’s pseudo Translation Lookaside Buffer, or pseudo-TLB. Under normal conditions, KVM must invalidate stale memory translations after memory mappings change.
Critical Linux KVM Flaw Lets Attackers Escape Virtual Machines and Gain Root Access
A critical security vulnerability in Linux’s Kernel-based Virtual Machine (KVM) subsystem could allow attackers to break out of affected virtual machines, access the underlying host, and potentially gain root privileges. Tracked as CVE-2026-89775, the flaw affects KVM on ARM64 systems when nested virtualization is enabled. Security researcher Hyunwoo Kim disclosed the issue after an embargo coordinated through the Linux distribution security process expired. The vulnerability is especially significant for multi-tenant cloud environments, where an attacker with access to a guest virtual machine may be able to compromise the host system that runs it. Critical Linux KVM Flaw From there, the attacker could potentially access other workloads, virtual machines, and sensitive cloud infrastructure hosted on the same physical server.
New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.
You've reached the end of current stories for this search.
