Last updated: October 5, 2026 at 10:28 AM UTC
All 897 Vulnerability 362 Breach 144 Threat 384 Defense 7
Tag: kvm (2 articles)Clear

Linux kernel ARM64 virtualization flaw lets guest machines read and write host memory

A flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave freed host memory exposed to a guest virtual machine when nested virtualization is enabled. Tracked as CVE-2026-89775, it lets a guest read and write host kernel memory, and the reporter says it can be used to escape the guest and run code on the host. A size calculation reaching zero skips a TLB invalidation, leaving a freed page mapped and writable with no hardware trap. It is fixed in Linux 6.18.51, 7.2.5, and 7.3-rc1. Nested virtualization is off by default and needs specific ARM hardware, and no exploitation is reported.

Check
Determine whether ARM64 KVM hosts enable experimental nested virtualization, then update to the patched kernel builds before relying on guest isolation there.
Affected
ARM64 KVM hosts running nested virtualization on affected kernels let a guest read and write freed host memory and potentially escape to the host.
Fix
Patch to Linux 6.18.51, 7.2.5, or 7.3-rc1, keep nested virtualization disabled where unneeded, and restrict access to /dev/kvm.

16-year-old KVM flaw lets a guest VM crash or escape to the Linux host

A use-after-free flaw in Linux's KVM hypervisor, nicknamed Januscape and hidden in the code for about 16 years, lets a virtual machine attack the physical host it runs on. Tracked as CVE-2026-53359, it sits in the shadow memory code that KVM uses on both Intel and AMD systems when nested virtualization is enabled. From inside a guest with root, an attacker can corrupt host kernel memory: the public proof-of-concept crashes the entire host, taking down every other tenant on that machine, and the researcher says a private exploit can run code as root on the host. The fix reached mainline Linux in June, and distributions are shipping updated kernels now.

Check
Identify x86 KVM hosts running untrusted or multi-tenant guests with nested virtualization enabled, check kernel versions against the Januscape fix, and confirm /dev/kvm is not world-writable on shared systems.
Affected
x86 KVM hosts on unpatched kernels with nested virtualization enabled (CVE-2026-53359), on both Intel and AMD; a guest with root can crash the host or potentially escape to run code on it.
Fix
Apply the updated kernels from your distribution as they ship. If you cannot patch immediately, disable nested virtualization with kvm_intel.nested=0 or kvm_amd.nested=0 to remove the attack path for untrusted guests.