Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Linux Zapscape Vulnerability Threatens KVM Hosts

New Linux Zapscape Vulnerability Threatens KVM Hosts

Posted on August 6, 2026 By CWS

A newly discovered vulnerability in the Linux kernel, named Zapscape, poses a significant threat to KVM hosts by allowing attackers with kernel privileges in an L1 guest virtual machine (VM) to escape isolation and execute code on the host system. This defect, identified as CVE-2026-64561, is particularly concerning when nested virtualization is accessible to untrusted guests.

Understanding the Zapscape Flaw

The Zapscape vulnerability affects the shadow memory management unit (MMU) of KVM/x86, which is responsible for managing shadow page tables crucial for nested guest memory translation. The security flaw, disclosed by researcher Hyunwoo Kim, enables an exploit path that can execute commands on the host with root privileges.

An upstream fix has been incorporated, advising administrators managing KVM hosts with exposed nested virtualization to apply a stable kernel patch or vendor-provided package updates. Notably, L1 kernel privilege typically requires guest root access, alongside specific conditions for Intel systems involving EPT page-walk lengths.

Technical Insights into the Flaw

The Zapscape issue is identified as a stale-root check ordering flaw within KVM’s shadow-MMU bookkeeping. This flaw can result in a use-after-free scenario during guest-triggered page fault handling. In these instances, KVM might reclaim MMU pages and invalidate the shadow MMU root page, failing to recheck the root, thus leading to continued operations under an invalidated root.

Kim’s technical assessment highlights a use-after-free in the recursive zap path during shadow page reclamation. Failure to revalidate the root can cause child shadow pages to inherit an invalid state, eventually leading to dangling links and potential post-free write vulnerabilities.

Proof-of-Concept and Industry Response

Kim has developed a proof-of-concept targeting AMD nested SVM/NPT on Linux 7.1.3, advising that it be safely executed under QEMU TCG. Although QEMU itself is not vulnerable, the bug resides within KVM’s kernel, independent of QEMU’s emulation. Kim states that while the proof-of-concept is public, there is no indication of the flaw being exploited in real-world scenarios.

The National Vulnerability Database has identified Linux versions 5.9 and later as affected, recommending updates to fixed stable releases. Red Hat has preliminarily rated the flaw with a CVSS score of 7.0, categorizing it as an expired pointer dereference.

Red Hat further advises that package statuses may vary across different Linux vendors, with backported fixes potentially present without version string updates. As of the latest reports, Debian’s tracker flags certain kernel packages as vulnerable, with others marked as fixed.

The disclosure timeline reveals that Kim reported the vulnerability to the kernel security team in July 2026, with the issue being publicly disclosed in early August following the assignment of CVE-2026-64561. The fix, now part of the kernel, modifies the stale-root check order to enhance system security.

The Hacker News Tags:AMD systems, CVE-2026-64561, Hyunwoo Kim, Intel systems, kernel privilege, KVM vulnerability, Linux kernel, Linux security, nested virtualization, proof-of-concept, Red Hat CVSS, shadow MMU, use-after-free, virtualization security, Zapscape flaw

Post navigation

Previous Post: Canadian Hacker Admits Guilt in U.S. Cloud Breach Case
Next Post: Thousands of Rockwell PLCs Put Water Systems at Risk

Related Posts

Learn a Smarter Way to Defend Modern Applications Learn a Smarter Way to Defend Modern Applications The Hacker News
China-Linked TA416 Intensifies Cyber Attacks on Europe China-Linked TA416 Intensifies Cyber Attacks on Europe The Hacker News
n8n Webhooks Exploited for Malware Delivery via Phishing n8n Webhooks Exploited for Malware Delivery via Phishing The Hacker News
Pre-Auth Exploit Chains Found in Commvault Could Enable Remote Code Execution Attacks Pre-Auth Exploit Chains Found in Commvault Could Enable Remote Code Execution Attacks The Hacker News
Security Tools Alone Don’t Protect You — Control Effectiveness Does Security Tools Alone Don’t Protect You — Control Effectiveness Does The Hacker News
Google Chrome Zero-Day CVE-2025-2783 Exploited by TaxOff to Deploy Trinper Backdoor Google Chrome Zero-Day CVE-2025-2783 Exploited by TaxOff to Deploy Trinper Backdoor The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Thousands of Rockwell PLCs Put Water Systems at Risk
  • New Linux Zapscape Vulnerability Threatens KVM Hosts
  • Canadian Hacker Admits Guilt in U.S. Cloud Breach Case
  • AI Memory Poisoning: The Threat of Hidden Prompts
  • Hackers Exploit Oracle Vulnerability to Control Windows Server

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Thousands of Rockwell PLCs Put Water Systems at Risk
  • New Linux Zapscape Vulnerability Threatens KVM Hosts
  • Canadian Hacker Admits Guilt in U.S. Cloud Breach Case
  • AI Memory Poisoning: The Threat of Hidden Prompts
  • Hackers Exploit Oracle Vulnerability to Control Windows Server

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark