AI description
CVE-2026-64561, dubbed "Zapscape," is a use-after-free vulnerability found in the Linux kernel's KVM virtualization code, specifically within the x86 shadow memory management unit (MMU). Discovered by researcher Hyunwoo Kim (@v4bel), the flaw stems from an incorrect ordering in page-fault handling. KVM checks the validity of the shadow MMU root before making MMU pages available; however, if shadow-page reclamation invalidates the in-use root during the subsequent page availability process, KVM can proceed to map memory using this now-stale root. This leads to the creation of invalid child shadow pages that are still added to the active MMU page list, violating KVM MMU invariants. Under specific conditions, such as when nested virtualization is enabled and an attacker has kernel-level control within a KVM guest, this vulnerability can be exploited to achieve a guest-to-host escape, allowing the attacker to execute code with root privileges on the host system. A public proof-of-concept exploit exists for Zapscape, which affects Linux kernels from version 5.9 onward.
- Description
- In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. If reclaiming shadow pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to map memory into an invalid root. On its own, populating an invalid root is "fine", but because child shadow pages inherit their parent's role, any children created during the map/fetch will be created as invalid pages, thus violating KVM's invariant that invalid pages are never on the list of active MMU pages. Note, the underlying flaw has existed since KVM first started tracking invalid roots in 2008 (commit 2e53d63acba7, "KVM: MMU: ignore zapped root pagetables"), but the true badness only came along in 2020 (Linux 5.9) with the invariant that invalid shadow pages can't be on the list of active pages. Note #2, inheriting role.invalid when creating child shadow pages is also far from ideal; that flaw will be addressed separately.
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 6
- Exploitability score
- 2
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity
- HIGH
- Hype score
- Not currently trending
CVE-2026-64561 Zapscape permite a invitados KVM escapar al host Linux con privilegios root Se ha descubierto una vulnerabilidad en el núcleo de Linux llamada Zapscape (CVE-2026-64561) https://t.co/Lks4hcDVvl
@elhackernet
10 Aug 2026
4718 Impressions
12 Retweets
49 Likes
10 Bookmarks
0 Replies
0 Quotes
CVE-2026-64561 https://t.co/oznSUBX0s9
@Mas73r
7 Aug 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PoC exploit code is public for CVE-2026-64561 (Zapscape), a KVM escape that runs commands with kernel root privilege on the host. Details inside. #KVM #Linux #CVE #Virtualization #CyberSecurity https://t.co/yDJEahiWID
@Daily_CyberSec
7 Aug 2026
477 Impressions
4 Retweets
7 Likes
0 Bookmarks
0 Replies
0 Quotes
Zapscape (CVE-2026-64561) in Linux KVM/x86 shadow-MMU can let a privileged L1 guest escape to the host and run code as root. Upstream fix already merged. #Zapscape #CVE-2026-64561 #KVM https://t.co/JdrLAdqFkP
@TweetThreatNews
6 Aug 2026
207 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Linux KVM'de yeni kritik VM Escape açığı duyuruldu ve PoC yayınlandı! Zapscape (CVE-2026-64561) adı verilen yeni güvenlik açığı, duyurulduktan bir kaç gün sonra PoC GitHub'da kamuya açık olarak paylaşıldı. PoC: https://t.co/guR6FIaQAJ Açık, nested vir
@ridvanyagli
6 Aug 2026
1528 Impressions
8 Retweets
25 Likes
11 Bookmarks
0 Replies
0 Quotes
🚨 Linux KVM'de yeni kritik VM Escape açığı duyuruldu ve PoC yayınlandı! Zapscape (CVE-2026-64561) adı verilen yeni güvenlik açığını duyuruldu ve hemen ardından PoC GitHub'da kamuya açık olarak paylaşıldı. PoC: https://t.co/guR6FIaiLb Açık, nested virtua
@ridvanyagli
6 Aug 2026
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Linux KVM'de yeni kritik VM Escape açığı duyuruldu ve PoC yayımlandı! Zapscape (CVE-2026-64561) adı verilen yeni güvenlik açığını duyuruldu ve hemen ardından PoC GitHub'da kamuya açık olarak paylaşıldı. PoC: https://t.co/guR6FIaQAJ Açık, nested virtua
@ridvanyagli
6 Aug 2026
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Linux KVM'de yeni kritik VM Escape açığı duyuruldu ve PoC yayımlandı! Zapscape (CVE-2026-64561) adı verilen yeni güvenlik açığını duyuruldu ve hemen ardından PoC GitHub'da kamuya açık olarak paylaşıldı. Açık, nested virtualization etkin olan KVM sistem
@ridvanyagli
6 Aug 2026
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2026-64561 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale"… https://t.co/VFWf5wAfub ----- Traducción: CVE-2026-64561 En … https://t.co/utmtNg
@infoflowcloud
4 Aug 2026
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes