cross-posted from: https://lemmy.world/post/50395277

Zapscape (CVE-2026-64561) is more than a guest-to-host escape. The vulnerability stems from an ordering flaw in KVM’s Shadow MMU page fault handling, where a stale root validation occurs before MMU quota reclaim. Under specific nested virtualization conditions, quota reclaim can invalidate the active shadow root while execution continues, leading to corrupted shadow page state, linked-list corruption, cross-cache reallocation, KASLR disclosure, and ultimately controlled host kernel code execution.

  • _hovi_
    link
    fedilink
    arrow-up
    3
    ·
    5 days ago

    Wonder when we’ll stop seeing so many of these back to back