In brief: A 16-year-old KVM vulnerability allows privileged code in guest VMs to escape to the host hypervisor.
A vulnerability has been discovered in Linux KVM that has existed for approximately 16 years and allows attackers to break out of a virtual machine and take control of the host. Intel and AMD x86 processors are affected.
A critical vulnerability has been uncovered in the Linux KVM hypervisor that has been present in the codebase for around 16 years. The vulnerability affects hardware virtualization on Intel and AMD x86 platforms. A successful exploit would allow an attacker to escape from an isolated guest VM and gain control over the host system.
For CISOs, hypervisor escapes are of particular relevance, since the isolation of guest VMs is a core component of security architecture in virtualization infrastructures. An escape from this isolation endangers all virtual machines running on the same host and potentially the entire hosting ecosystem.
Fixing this long-standing vulnerability requires coordination between kernel maintainers, distributors, and organizations operating KVM-based infrastructure. Systems should be updated to patched kernel versions as soon as they become available.
Source: www.security-insider.de · Published 13 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.