Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Linux Flaw Allows KVM Escape with Root Access

Critical Linux Flaw Allows KVM Escape with Root Access

Posted on August 7, 2026 By CWS

A significant vulnerability in the Linux kernel, identified as CVE-2026-64561 and dubbed Zapscape, poses a serious threat by potentially enabling attackers to escape from a KVM virtual machine and gain root-level control over the Linux host.

Understanding the Zapscape Vulnerability

This security flaw impacts KVM/x86, a popular virtualization technology that isolates guest systems from the physical server. The vulnerability is particularly alarming for cloud service providers and businesses that run untrusted workloads, as it could lead to unauthorized access and control.

Security researcher Hyunwoo Kim, also known as V4bel, discovered Zapscape within the shadow memory management unit (MMU) of KVM. This component is crucial for managing memory translations during nested virtualization, which allows one virtual machine to host another. While beneficial for testing and cloud services, it also expands the potential attack surface.

Technical Details and Exploitation Risks

The flaw is categorized as a use-after-free bug in KVM’s recursive zap path, occurring when shadow pages are reclaimed. This error can lead to the reuse of freed memory structures, creating a security risk.

An attacker operating from a guest environment could exploit this flaw to corrupt memory in the host kernel, breaching the security boundary that typically isolates a guest from its host. Such an attack could enable the execution of commands on the host with root privileges, leading to data theft, service interruption, and unauthorized access to other virtual machines on the same server.

Mitigation and Future Outlook

The vulnerability’s proof-of-concept, demonstrated on GitHub, shows the escape mechanism in a controlled QEMU TCG setting, resulting in a root-owned file on the host. Although not ready for immediate cloud attacks, it highlights the need for urgent patching.

The code vulnerability was introduced in 2020 and addressed in Linux commit 2abd5287f083 on July 21, 2026. The patch modifies the validation sequence in the shadow MMU fault path, ensuring that KVM rechecks the validity of a root page before proceeding.

Administrators are urged to apply vendor-supplied kernel updates and reboot affected systems promptly. Until patches are in place, disabling nested virtualization for untrusted users and restricting access to /dev/kvm is advised. Furthermore, reviewing host configurations and monitoring vendor advisories are crucial steps in mitigating risks.

Ultimately, the Zapscape incident underscores the critical importance of hypervisor patch management, as a single guest escape can compromise isolation across an entire server.

Cyber Security News Tags:cloud security, CVE-2026-64561, hypervisor security, KVM vulnerability, Linux security, nested virtualization, root access, security patch, Use-After-Free bug, Zapscape

Post navigation

Previous Post: Critical WordPress XSS Flaw Patched: Urgent Update Advised
Next Post: Critical Linux SCTP Vulnerability Allows Root Access

Related Posts

Avast Antivirus Vulnerability Exposed by Chaotic Eclipse Avast Antivirus Vulnerability Exposed by Chaotic Eclipse Cyber Security News
PoC Exploit Released for Remotely Exploitable Oracle E-Business Suite 0-Day Vulnerability PoC Exploit Released for Remotely Exploitable Oracle E-Business Suite 0-Day Vulnerability Cyber Security News
US Confirms Shutdown of BlackSuit Ransomware That Hacked Over 450 Organizations US Confirms Shutdown of BlackSuit Ransomware That Hacked Over 450 Organizations Cyber Security News
Prometei Botnet Attacking Linux Servers to Mine Cryptocurrency Prometei Botnet Attacking Linux Servers to Mine Cryptocurrency Cyber Security News
Malware Campaign Exploits SEO to Target IT Professionals Malware Campaign Exploits SEO to Target IT Professionals Cyber Security News
New Android Malware GhostSpy Let Attacker Take Full Control Over Infected Devices New Android Malware GhostSpy Let Attacker Take Full Control Over Infected Devices Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in OpenShift Allows Malicious Releases
  • Zero-Day Tool Blocks Microsoft Defender Updates
  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in OpenShift Allows Malicious Releases
  • Zero-Day Tool Blocks Microsoft Defender Updates
  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark