Bottom line: CVE-2026-64561 (Zapscape) allows attackers with kernel privileges in an L1 guest VM to break out of KVM onto the Linux host, provided nested virtualization is enabled for untrusted guests.
A new Linux kernel vulnerability named Zapscape allows attackers with kernel privileges inside an L1 guest VM to break through KVM isolation and execute code on the host system. Environments in which nested virtualization is accessible to untrusted guests are affected.
The vulnerability is tracked as CVE-2026-64561 and affects the Shadow Memory Management Unit (Shadow MMU) of KVM/x86, which is responsible for managing so-called shadow page tables. This component is used in nested virtualization, where additional virtual machines (L2) are run within a virtual machine (L1). An attacker who already has kernel privileges within the L1 guest VM can exploit the vulnerability to overcome KVM’s isolation boundaries and execute code directly on the underlying Linux host.
For CISOs, it is relevant that the risk exists specifically in scenarios involving nested virtualization where L1 guests are not fully trusted — for example, at cloud providers offering nested VMs to customers, or in internal test environments with multi-tenant use. If the escape succeeds, an attacker can gain control over the hypervisor host and thereby potentially access all VMs running on that host as well as data belonging to other tenants. This represents a classic case of isolation failure in virtualized multi-tenant infrastructures, with corresponding consequences for confidentiality and integrity across tenant boundaries.
Affected organizations should check whether and where nested virtualization is actively used, particularly in cloud or hosting environments with third-party or partially trusted guest workloads. Until an official patch for the affected Linux kernel code is available, it is recommended as an interim measure to disable nested virtualization for untrusted guests or restrict the corresponding feature flags. Security teams should keep an eye on kernel release notes and distribution advisories regarding CVE-2026-64561 in order to update to patched kernel versions as soon as possible.
Source: thehackernews.com · Published August 6, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.