Linux KVM ARM64 Flaw Lets Guests Read and Write Host Memory
A flaw in the Linux kernel's KVM virtualization code for ARM64, tracked as CVE-2026-89775, leaves a freed piece of host memory exposed to guest VMs when nested virtualization is enabled. A guest can read and write host kernel memory, and the researcher says it can be used to escape the VM and run code on the host.
- CVE-2026-89775 affects KVM for ARM64 in the Linux kernel
- A guest can read and write host kernel memory
- The bug requires nested virtualization to be enabled
- Researcher says it allows VM escape and code execution on the host
Read next
Security