What is CVE-2026-64561?
Tracked as CVE-2026-64561, Zapscape is a new Linux kernel vulnerability in the KVM subsystem that allows an attacker with kernel privileges inside an L1 guest VM to escape isolation and execute code on the host. This flaw poses a risk when nested virtualization is exposed to untrusted guests, requiring immediate patching.
Azərbaycanca: CVE-2026-64561 Linux kernel-in KVM (Kernel-based Virtual Machine) alt sistemində aşkar edilmiş Zapscape zəifliyidir. Bu qüsur, L1 qonaq virtual maşınında kernel səviyyəli imtiyazlara malik təcavüzkara KVM izolyasiyasını aşaraq host sistemində kod icra etməyə imkan verir. Xüsusilə nested virtuallaşdırmanın etibarsız qonaqlara təqdim edildiyi mühitlər risk altındadır və dərhal yamaqlar tətbiq edilməlidir.
FAQ2
In which Linux subsystem was CVE-2026-64561 discovered?
CVE-2026-64561 was discovered in the KVM (Kernel-based Virtual Machine) subsystem of the Linux kernel.
What can an attacker achieve by exploiting the Zapscape vulnerability?
An attacker with kernel privileges inside an L1 guest VM can escape KVM isolation and execute code on the host system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.