Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Linux Flaw Allows KVM Escape with Root Access

Critical Linux Flaw Allows KVM Escape with Root Access

Posted on August 7, 2026 By CWS

A significant vulnerability in the Linux kernel, identified as CVE-2026-64561 and dubbed Zapscape, poses a serious threat by potentially enabling attackers to escape from a KVM virtual machine and gain root-level control over the Linux host.

Understanding the Zapscape Vulnerability

This security flaw impacts KVM/x86, a popular virtualization technology that isolates guest systems from the physical server. The vulnerability is particularly alarming for cloud service providers and businesses that run untrusted workloads, as it could lead to unauthorized access and control.

Security researcher Hyunwoo Kim, also known as V4bel, discovered Zapscape within the shadow memory management unit (MMU) of KVM. This component is crucial for managing memory translations during nested virtualization, which allows one virtual machine to host another. While beneficial for testing and cloud services, it also expands the potential attack surface.

Technical Details and Exploitation Risks

The flaw is categorized as a use-after-free bug in KVM’s recursive zap path, occurring when shadow pages are reclaimed. This error can lead to the reuse of freed memory structures, creating a security risk.

An attacker operating from a guest environment could exploit this flaw to corrupt memory in the host kernel, breaching the security boundary that typically isolates a guest from its host. Such an attack could enable the execution of commands on the host with root privileges, leading to data theft, service interruption, and unauthorized access to other virtual machines on the same server.

Mitigation and Future Outlook

The vulnerability’s proof-of-concept, demonstrated on GitHub, shows the escape mechanism in a controlled QEMU TCG setting, resulting in a root-owned file on the host. Although not ready for immediate cloud attacks, it highlights the need for urgent patching.

The code vulnerability was introduced in 2020 and addressed in Linux commit 2abd5287f083 on July 21, 2026. The patch modifies the validation sequence in the shadow MMU fault path, ensuring that KVM rechecks the validity of a root page before proceeding.

Administrators are urged to apply vendor-supplied kernel updates and reboot affected systems promptly. Until patches are in place, disabling nested virtualization for untrusted users and restricting access to /dev/kvm is advised. Furthermore, reviewing host configurations and monitoring vendor advisories are crucial steps in mitigating risks.

Ultimately, the Zapscape incident underscores the critical importance of hypervisor patch management, as a single guest escape can compromise isolation across an entire server.

Cyber Security News Tags:cloud security, CVE-2026-64561, hypervisor security, KVM vulnerability, Linux security, nested virtualization, root access, security patch, Use-After-Free bug, Zapscape

Post navigation

Previous Post: Critical WordPress XSS Flaw Patched: Urgent Update Advised

Related Posts

Hackers Exploiting RMM Tools LogMeIn and PDQ Connect to Deploy Malware as a Normal Program Hackers Exploiting RMM Tools LogMeIn and PDQ Connect to Deploy Malware as a Normal Program Cyber Security News
BreachLock Recognized in 2026 Gartner AEV Guide BreachLock Recognized in 2026 Gartner AEV Guide Cyber Security News
FBI Captures Contractor for  Million Cryptocurrency Theft FBI Captures Contractor for $46 Million Cryptocurrency Theft Cyber Security News
Malicious npm Packages Compromise Security Malicious npm Packages Compromise Security Cyber Security News
Best MSP Software: The Essential Tech Stack  Best MSP Software: The Essential Tech Stack  Cyber Security News
ChatGPT Lockdown Mode Enhances Security Against Data Threats ChatGPT Lockdown Mode Enhances Security Against Data Threats Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Linux Flaw Allows KVM Escape with Root Access
  • Critical WordPress XSS Flaw Patched: Urgent Update Advised
  • Patchwork’s Espionage via Fake PDFs and Chat Apps
  • Microsoft and Apple Launch Key Security Updates
  • Open Source Faces Challenges and Evolves

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Linux Flaw Allows KVM Escape with Root Access
  • Critical WordPress XSS Flaw Patched: Urgent Update Advised
  • Patchwork’s Espionage via Fake PDFs and Chat Apps
  • Microsoft and Apple Launch Key Security Updates
  • Open Source Faces Challenges and Evolves

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark