← Back

Wire · technology

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Published

7 August 2026

Topic

technology

Sectors

Cloud Infrastructure

Source

Read at thehackernews.com

Verified

Fusion42 · 30 August 2026 · Fusion42 review

A Linux kernel vulnerability named Zapscape (CVE-2026-64561) could enable an attacker with kernel privileges inside an L1 guest VM to escape KVM isolation and execute code on the host. The flaw affects nested virtualization on KVM/x86 shadow memory management and has been fixed upstream; hosts exposing nested virtualization should update their kernels promptly.

This Wire brief sits within Fusion42's coverage of Cloud Infrastructure.

◆ The Wire takeaway

Your Linux virtualisation hosts face a critical risk from nested guest escape vulnerabilities and must update kernels immediately to block host compromise. The attack path requires kernel access inside guests, exposing a direct host takeover route if unpatched.

Coverage

1 source · 7 Aug 2026

Related on Wire

Topics

Cloud Infrastructurelinux-kernelkvmvirtualization-securityvulnerabilitynested-virtualizationzapscape