A newly disclosed KVM/x86 vulnerability, CVE-2026-64561 or Zapscape, allows a privileged L1 guest to break nested virtualization isolation and achieve guest-to-host escape on Linux systems. The bug is a use-after-free in KVM/x86 shadow MMU emulation tied to the recursive shadow-page zap path and stale-root check ordering during guest-triggered page fault handling, enabling corruption of host kernel shadow pages and potential host code execution. Researcher Hyunwoo Kim reported the flaw to the Linux kernel security team and published a proof-of-concept showing creation of a root-owned file on the host.
The issue affects both Intel and AMD hosts and is especially serious for environments that run untrusted guests with nested virtualization enabled, including multi-tenant public cloud infrastructure. On Intel, exploitation requires exposing both EPT page walk lengths 4 and 5 to the L1 guest, while no equivalent constraint was noted for AMD. The vulnerability affects Linux KVM versions from 5.9 onward across the disclosed commit range, and a fix has been merged upstream into mainline Linux, with users advised to deploy patched stable kernels or vendor-backported updates; no in-the-wild exploitation has been claimed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
As of August 6, Debian's security tracker listed bullseye, bookworm, trixie, and forky kernel packages as vulnerable to CVE-2026-64561, while sid included the fix starting with version 7.1.6-1. This provided a concrete downstream distribution status update for Zapscape.
After the linux-distros embargo expired, Hyunwoo Kim publicly disclosed Zapscape on oss-sec and published a proof-of-concept demonstrating host-level impact by creating a root-owned file named /Zapscape. The disclosure described the flaw as a use-after-free in KVM/x86 shadow MMU emulation affecting Intel and AMD hosts.
The Zapscape KVM/x86 guest-to-host escape vulnerability received the identifier CVE-2026-64561.
The vulnerability was submitted to the linux-distros list under a five-day embargo ahead of public disclosure.
A patch for the stale-root check ordering bug in KVM/x86 was posted and merged upstream as commit 2abd5287f083. The fix moves the stale-root check after make_mmu_pages_available() so KVM retries the fault if reclaim invalidates the current root.
Hyunwoo Kim reported the KVM/x86 guest-to-host escape vulnerability to security@kernel.org. The issue was later tracked as CVE-2026-64561.
The affected code range for Zapscape begins with Linux commit f95eec9bed76, marking the introduction of the vulnerable KVM/x86 shadow MMU logic later tracked as CVE-2026-64561.
The fix for CVE-2026-64561 was released in upstream stable Linux kernel versions 6.1.148, 6.18.42, and 6.6.148. The reference also notes related advisories or updates from Debian, Ubuntu, SUSE/openSUSE, RHEL, Gentoo, Arch, and Fedora.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcecybersecuritynews.com
Open sourcethecybersecguru.com
Open sourceopennet.ru
Open sourceseclists.org
Open sourcegithub.com
Open sourcebugzilla.redhat.com
Open sourcesecurity-tracker.debian.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.