HomeSecurityLinux Kernel Vulnerability Allows Access to ARM64 KVM Guests

Linux kernel vulnerability allows access to ARM64 KVM Guests

A new vulnerability in the Linux kernel's KVM virtualization code for ARM64 could leave a freed chunk of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled.

See also: 9-year-old Linux Kernel vulnerability allows root access

Article image: New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

The flaw, tracked as CVE-2026-89775, allows a guest to read and write to the host kernel memory, and the researcher who discovered it says it can be used to escape the guest and execute code on the host machine. The affected code is part of the main Linux kernel for ARM64 and has been fixed in Linux versions 6.18.51, 7.2.5, and 7.3-rc1.

Nested virtualization allows a guest to run its own hypervisor, allowing it to host virtual machines. On ARM64, it is disabled by default. It is an experimental boot-time feature that requires Armv8.4 hardware with a feature called FEAT_NV2, so a simple ARM64 KVM host that never enables it is outside the attack path mentioned.

The vulnerability lies in the part of KVM that handles nested virtualization on ARM64. When a guest configures its memory in a certain way, a size calculation returns zero, and a step that should clear old entries from the processor's address cache, a TLB invalidation, is skipped.

A freed host memory page then remains mapped and writable, and the guest can read and write it 64 bits at a time, without a hardware trap to return control to the host.

Hyunwoo Kim, the security researcher who reported the vulnerability and disclosed it on September 16, says that a guest could use this to escape to the host, escaping from its own virtual machine to execute code on the host machine. No exploit code has been published, and there is no indication that the vulnerability has been used in an attack.

See also: CVE-2026-53266: Critical vulnerability in Linux Kernel's ebtables SNAT

Linux ARM64 vulnerability - SecNews.gr

There is a second way to exploit the vulnerability. On systems where any user can open /dev/kvm, the device a program uses to create a virtual machine, a local user could create a guest and use the same flaw to gain root access, Kim says.

It mentions Red Hat Enterprise Linux, where this device is open to all users by default. Red Hat lists its kernel version 10 as affected and versions 6 through 9 as unaffected. This route still requires the host to have nested virtualization enabled. Upstream, the vulnerability has been fixed in Linux versions 6.18.51, 7.2.5, and 7.3-rc1. Distributions ship the fix with their own packages, and the status varies by version.

For hosts that cannot yet be patched, Red Hat says that no mitigation meets its criteria for an alternative solution. The only thing that is certain is the scope: the attack only targets hosts with nested virtualization enabled, which is not the default on ARM64.

Vendors rate the vulnerability from 7.8 to 9.3 out of 10.They agree that the impact is high and the attack is local, meaning it cannot be launched over a network. The difference reflects how difficult each vendor considers the vulnerability to be to exploit, with Ubuntu, which rates it at 9.3, setting its priority at medium. As of September 22, the vulnerability was not on the U.S. CISA list of exploitable vulnerabilities, and the predicted exploit score was below 1%.

The disclosure raises the question of whether cloud tenants could use the vulnerability to compromise a provider's machines. At larger providers, the necessary configuration is not offered: Amazon Web Services only lists Intel-based instances for nested virtualization, and Google Cloud excludes ARM virtual machines from it.

See also: ZcopyReaper: Critical vulnerability in Linux Kernel leads to root access

Linux kernel vulnerability allows access to ARM64 KVM Guests

CVE-2026-89775 is the fourth guest-to-host KVM exploit that Kim has disclosed this year. Two were in the x86 version of KVM: Januscape in July and Zapscape in August. The most similar one is ITScape, an ARM64 KVM exploit he published in June, which he called the first such exploit publicly published on ARM64.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS