Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: nested-virtualization (1 article)Clear

Linux kernel ARM64 virtualization flaw lets guest machines read and write host memory

A flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave freed host memory exposed to a guest virtual machine when nested virtualization is enabled. Tracked as CVE-2026-89775, it lets a guest read and write host kernel memory, and the reporter says it can be used to escape the guest and run code on the host. A size calculation reaching zero skips a TLB invalidation, leaving a freed page mapped and writable with no hardware trap. It is fixed in Linux 6.18.51, 7.2.5, and 7.3-rc1. Nested virtualization is off by default and needs specific ARM hardware, and no exploitation is reported.

Check
Determine whether ARM64 KVM hosts enable experimental nested virtualization, then update to the patched kernel builds before relying on guest isolation there.
Affected
ARM64 KVM hosts running nested virtualization on affected kernels let a guest read and write freed host memory and potentially escape to the host.
Fix
Patch to Linux 6.18.51, 7.2.5, or 7.3-rc1, keep nested virtualization disabled where unneeded, and restrict access to /dev/kvm.