Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical ARM64 Linux Vulnerability Exposes Hosts

Critical ARM64 Linux Vulnerability Exposes Hosts

Posted on September 22, 2026 By CWS

A recently revealed vulnerability within the Linux kernel, identified as CVE-2026-89775, presents a significant security threat by allowing attackers to break out of ARM64 virtual machines and gain access to the host system.

Impact on KVM/arm64 Environments

This vulnerability primarily affects KVM/arm64 setups where nested virtualization is activated. The flaw poses a considerable risk to multi-tenant cloud environments and systems that permit untrusted users to generate virtual machines.

Security expert Hyunwoo Kim uncovered that the issue arises from a type truncation problem during the KVM/arm64 stage-1 page-table walk process. This bug affects the kernel’s method of determining the memory region size that needs invalidation in the virtual CPU’s pseudo Translation Lookaside Buffer (pseudo-TLB).

Technical Details of the Flaw

Typically, KVM must invalidate obsolete memory translations post memory mapping changes to prevent a guest virtual machine from accessing memory released or reallocated by the host kernel. However, in the flawed code path, the size calculation can incorrectly return 0, signifying an unknown memory size. The pseudo-TLB invalidation logic erroneously interprets this as a valid range, resulting in an empty invalidation range and skipping the necessary operation. This oversight allows stale memory information to be accessed by a malicious guest.

The vulnerability can lead to a freed host memory page remaining mapped as writable at a fixed host-kernel address. This situation permits a malicious guest to gain 64-bit read and write access to that page, bypassing traps or virtual machine exits, thus enabling direct host memory manipulation.

Security Implications and Mitigation Strategies

The vulnerability is particularly concerning for public cloud deployments utilizing ARM64 infrastructure. An attacker with nested virtualization capabilities could potentially transition from a guest system to the host, breaching the isolation between a customer’s virtual machine and the cloud provider’s infrastructure.

This flaw also presents a local privilege-escalation risk. Some distributions, such as certain Red Hat Enterprise Linux configurations, may expose /dev/kvm with world-writable permissions, allowing unprivileged local users to exploit the flaw for root access on the host.

The vulnerability originated from Linux kernel code introduced by commit 7270cc9157f47 on May 14, 2025, and was rectified upstream by commit 8053393680d4 on August 6, 2026. Administrators are advised to update to a kernel release featuring the mainline fix once available from their distribution vendor.

Organizations using ARM64 KVM hosts should evaluate the necessity of nested virtualization and consider disabling it to minimize exposure while patches are applied. Cloud providers need to prioritize patching shared infrastructure, assess tenant access to nested virtualization, and verify /dev/kvm permissions to curtail local attack vectors. The Linux mainline kernel now includes a patch addressing this vulnerability.

Cyber Security News Tags:ARM64, cloud infrastructure, CVE-2026-89775, Kernel, KVM, Linux, nested virtualization, Security, Virtualization, Vulnerability

Post navigation

Previous Post: Chinese Hackers Exploit ZyXEL Switch Vulnerability
Next Post: Critical Linux Kernel Bug Threatens ARM64 Systems

Related Posts

Ghost CMS Vulnerability Exploited in Widespread Malware Attack Ghost CMS Vulnerability Exploited in Widespread Malware Attack Cyber Security News
Python-powered Toolkit for Information Gathering and reconnaissance Python-powered Toolkit for Information Gathering and reconnaissance Cyber Security News
Your Tier 1 Analyst at SOC Team Is Failing at Effective Triage Your Tier 1 Analyst at SOC Team Is Failing at Effective Triage Cyber Security News
Weaver E-cology RCE Flaw Under Active Exploitation Weaver E-cology RCE Flaw Under Active Exploitation Cyber Security News
Microsoft Teams to Auto-Set Work Location by Detecting the Wi-Fi Network Microsoft Teams to Auto-Set Work Location by Detecting the Wi-Fi Network Cyber Security News
New ‘SleepyDuck’ Malware in Open VSX Marketplace Allow Attackers to Control Windows Systems Remotely New ‘SleepyDuck’ Malware in Open VSX Marketplace Allow Attackers to Control Windows Systems Remotely Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards
  • Malicious NPM Package Threatens Supply Chain Security
  • SharePoint Vulnerability Allows Remote Code Execution
  • Critical SharePoint Flaw Enables Remote Code Execution
  • Cyera Secures $400M, Reaches $12B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards
  • Malicious NPM Package Threatens Supply Chain Security
  • SharePoint Vulnerability Allows Remote Code Execution
  • Critical SharePoint Flaw Enables Remote Code Execution
  • Cyera Secures $400M, Reaches $12B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark