Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Linux Kernel Bug Threatens ARM64 Systems

Critical Linux Kernel Bug Threatens ARM64 Systems

Posted on September 22, 2026 By CWS

A serious vulnerability in the Linux kernel’s KVM virtualization component for ARM64 processors has been identified, potentially allowing guest virtual machines to access host memory on systems with nested virtualization enabled. The flaw, labeled as CVE-2026-89775, enables a guest to read and write host kernel memory, posing a risk of guest-to-host escape to execute code on the host machine.

Understanding the Linux Kernel Flaw

This vulnerability affects the mainline Linux kernel for ARM64 and has been addressed in versions 6.18.51, 7.2.5, and 7.3-rc1. Nested virtualization, which allows a guest to run its own hypervisor, is off by default on ARM64 systems. It requires Armv8.4 hardware with the FEAT_NV2 feature enabled. A plain ARM64 KVM host that does not activate this feature is not susceptible to the described attack.

The issue lies in how KVM manages nested virtualization on ARM64. When a guest structures its memory in a specific manner, a calculation error occurs, leading to skipped TLB invalidation, which leaves a page of freed host memory mapped and writable. This oversight allows the guest to manipulate the memory without triggering a hardware trap.

Potential Exploitation and Security Concerns

Security researcher Hyunwoo Kim, who discovered and reported the flaw on September 16, notes that a guest could exploit this vulnerability to escape its virtual environment and execute code on the host machine. As of now, no exploit code has been disclosed, and there is no evidence of the flaw being actively exploited in attacks.

The kernel’s records show the affected code is present from version 6.16, but the actual exploitable behavior begins in version 6.17. Additionally, on systems where /dev/kvm is accessible to all users, a local user could potentially exploit the flaw to gain root access, particularly in environments like Red Hat Enterprise Linux.

Fixes and Vendor Responses

Upstream, the flaw has been rectified in Linux 6.18.51, 7.2.5, and 7.3-rc1, with distributions releasing patches according to their schedules. For example, Red Hat acknowledges the issue in version 10 of its kernel, while Ubuntu has identified certain AWS, Azure, and GCP kernels as vulnerable. Meanwhile, Amazon Linux is working on a fix for its AL2023 kernel6.18 package.

For installations that cannot yet be patched, Red Hat reports a lack of viable workarounds. Notably, the attack vector targets only systems with nested virtualization enabled, which is not standard on ARM64. Vendors have rated the flaw’s severity between 7.8 and 9.3 out of 10, with the consensus being that while the impact is significant, the attack is local and not network-exploitable.

As of September 22, the flaw remains absent from the U.S. CISA’s catalog of exploited vulnerabilities, with its likelihood of exploitation rated below 1%. The flaw raises concerns about potential security risks for cloud providers, though leading services like Amazon Web Services and Google Cloud do not offer nested virtualization configurations for ARM instances, mitigating immediate risk exposure.

The Hacker News Tags:ARM64, CVE-2026-89775, Debian, Kernel, KVM, Linux, Red Hat, Security, Ubuntu, Virtualization, Vulnerability

Post navigation

Previous Post: Critical ARM64 Linux Vulnerability Exposes Hosts
Next Post: Cyera Secures $400M, Reaches $12B Valuation

Related Posts

JackFix Uses Fake Windows Update Pop-Ups on Adult Sites to Deliver Multiple Stealers JackFix Uses Fake Windows Update Pop-Ups on Adult Sites to Deliver Multiple Stealers The Hacker News
North Korean Hackers Exploit npm Packages for Malware North Korean Hackers Exploit npm Packages for Malware The Hacker News
China-Linked Hackers Exploit New VMware Zero-Day Since October 2024 China-Linked Hackers Exploit New VMware Zero-Day Since October 2024 The Hacker News
OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps The Hacker News
Microsoft Secures Defender Against Critical Privilege Flaw Microsoft Secures Defender Against Critical Privilege Flaw The Hacker News
Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards
  • Malicious NPM Package Threatens Supply Chain Security
  • SharePoint Vulnerability Allows Remote Code Execution
  • Critical SharePoint Flaw Enables Remote Code Execution
  • Cyera Secures $400M, Reaches $12B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards
  • Malicious NPM Package Threatens Supply Chain Security
  • SharePoint Vulnerability Allows Remote Code Execution
  • Critical SharePoint Flaw Enables Remote Code Execution
  • Cyera Secures $400M, Reaches $12B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark