New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
PatchLinux KernelKVMOur summary
CVE-2026-89775 in Linux Kernel ARM64 KVM can let a guest virtual machine retain read-write access to freed host kernel memory when nested virtualization is enabled, potentially enabling a guest-to-host escape. The issue is fixed in Linux 6.18.51, 7.2.5, and 7.3-rc1; no exploitation or public exploit code has been reported, and ARM64 nested virtualization is disabled by default.
Read at The Hacker News
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.