CVE-2026-89775 is a guest-to-host escape vulnerability in Linux KVM on ARM64 systems with nested virtualization enabled. A stage-1 page-table walk-level truncation can cause a range-size calculation to return zero; VNCR pseudo-TLB invalidation then skips invalidation, potentially leaving a freed host page mapped and writable at a fixed host-kernel address. A malicious guest can obtain 64-bit read/write access to host kernel memory and may be able to execute code on the host.
The issue affects multi-tenant ARM64 cloud deployments that expose nested-virtualization-capable instances and local systems where unprivileged users can access /dev/kvm. Nested virtualization is experimental, disabled by default, and requires Armv8.4 FEAT_NV2 hardware, limiting exposure. Upstream fixed the flaw in commit 8053393680d4; fixes are available in Linux 6.18.51, 7.2.5, and 7.3-rc1. No public exploit or active exploitation had been reported.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The affected upstream Linux kernel code was introduced in commit 7270cc9157f47, establishing the code path later identified as vulnerable to missed pseudo-TLB invalidation under nested virtualization.
Researcher Hyunwoo Kim disclosed CVE-2026-89775, a KVM/arm64 nested-virtualization flaw that can skip required TLB invalidation and leave freed host memory mapped writable to a guest. The issue could permit 64-bit guest reads and writes to host kernel memory and potentially enable guest-to-host escape.
Linux mainline incorporated commit 8053393680d4 to fix the KVM/arm64 nested-virtualization flaw. Upstream fixes were subsequently available in Linux 6.18.51, 7.2.5, and 7.3-rc1.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.