Skip to content
archivevulnerability · 22 Sep 2026 · 11:38 UTC

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

VULNCVE-2026-89775source · THN

last 60 dispatches · spectrum

A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.

CVE · detail
grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected