A flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave freed host memory exposed to a guest virtual machine when nested virtualization is enabled. Tracked as CVE-2026-89775, it lets a guest read and write host kernel memory, and the reporter says it can be used to escape the guest and run code on the host. A size calculation reaching zero skips a TLB invalidation, leaving a freed page mapped and writable with no hardware trap. It is fixed in Linux 6.18.51, 7.2.5, and 7.3-rc1. Nested virtualization is off by default and needs specific ARM hardware, and no exploitation is reported.
A use-after-free flaw in Linux's KVM hypervisor, nicknamed Januscape and hidden in the code for about 16 years, lets a virtual machine attack the physical host it runs on. Tracked as CVE-2026-53359, it sits in the shadow memory code that KVM uses on both Intel and AMD systems when nested virtualization is enabled. From inside a guest with root, an attacker can corrupt host kernel memory: the public proof-of-concept crashes the entire host, taking down every other tenant on that machine, and the researcher says a private exploit can run code as root on the host. The fix reached mainline Linux in June, and distributions are shipping updated kernels now.