{"id":12036,"date":"2026-08-07T15:10:27","date_gmt":"2026-08-07T21:10:27","guid":{"rendered":"https:\/\/beaconlab.us\/publicacion\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\/"},"modified":"2026-09-29T17:00:13","modified_gmt":"2026-09-29T23:00:13","slug":"alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape","status":"publish","type":"publicacion","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\/","title":{"rendered":"Alert 2026-86 Virtual Machine Escape with Host RCE in the Linux KVM Kernel (&#8220;Zapscape&#8221;)"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Affected product(s):<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>Linux Kernel \u2014 KVM\/x86 Subsystem<\/strong> (Kernel-based Virtual Machine)<\/p>\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Product<\/strong><\/td><td><strong>Affected versions<\/strong><\/td><td><strong>Fixed version<\/strong><\/td><\/tr><tr><td><strong>Linux Kernel (mainline)<\/strong><\/td><td>5.9 through 7.1.5<\/td><td>7.1.6<\/td><\/tr><tr><td><strong>Linux Kernel (stable 6.18.x)<\/strong><\/td><td>6.18 through 6.18.41<\/td><td>6.18.42<\/td><\/tr><tr><td><strong>Linux Kernel (stable 6.12.x)<\/strong><\/td><td>6.12 through 6.12.100<\/td><td>6.12.101<\/td><\/tr><tr><td><strong>Linux Kernel (stable 6.6.x LTS)<\/strong><\/td><td>6.6 through 6.6.147<\/td><td>6.6.148<\/td><\/tr><tr><td><strong>Red Hat \/ RHEL<\/strong><\/td><td>Versions with affected KVM<\/td><td>Update pending<\/td><\/tr><tr><td><strong>Debian (bullseye, bookworm, trixie)<\/strong><\/td><td>All current branches<\/td><td>Patch in distribution<\/td><\/tr><tr><td><strong>CloudLinux 7h, 8, 9, 10<\/strong><\/td><td>Affected<\/td><td>Patch published<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<h2 class=\"wp-block-heading\">Description<\/h2>\n\n<p class=\"wp-block-paragraph\">A <em>use-after-free<\/em> vulnerability has been disclosed in the <strong>KVM\/x86<\/strong> subsystem of the Linux kernel. It has been identified as CVE-2026-64561 with a CVSSv3.1 score of 7.0 \u2014 Important; the researcher named it Zapscape,<\/p>\n\n<p class=\"wp-block-paragraph\">The flaw allows an attacker with <strong>root privileges inside a guest virtual machine (L1)<\/strong>, on systems with <strong>nested virtualization enabled<\/strong>, to escape the VM isolation and execute arbitrary code with <strong>root privileges on the physical host<\/strong>.<\/p>\n\n<p class=\"wp-block-paragraph\">Unlike previous similar vulnerabilities, Zapscape is exploitable on both <strong>Intel (Ice Lake-SP and later)<\/strong> and <strong>AMD<\/strong> processors, significantly expanding the attack surface.<\/p>\n\n<p class=\"wp-block-paragraph\">The flaw resides in an <strong>incorrect validation order<\/strong> in the handling of guest page faults within KVM\/x86&#8217;s shadow MMU. When KVM attempts to reuse a shadow page, it does not properly check whether the <em>page root<\/em> had already been marked as invalid by the memory reclamation process (make_mmu_pages_available()).<\/p>\n\n<p class=\"wp-block-paragraph\">If the reclaim invalidates the active root, KVM continues attempting to map memory within that invalid root. As a consequence, the child shadow pages created during the process inherit the invalid state from the parent, <strong>violating KVM&#8217;s internal invariant<\/strong> which states that invalid pages must never be in the active MMU pages list. This generates a memory corruption condition exploitable for VM escape.<\/p>\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"572\" src=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/08\/download-1024x572.png\" alt=\"\" class=\"wp-image-11668\" srcset=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/08\/download-1024x572.png 1024w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/08\/download-300x167.png 300w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/08\/download-768x429.png 768w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/08\/download.png 1376w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n<p class=\"has-text-align-center wp-block-paragraph\">Figure 1 &#8211; Privilege Escalation in Virtualization: KVM Guest-to-Host Attack Vectors<\/p>\n\n<p class=\"wp-block-paragraph\">Additionally, the <strong>PoC (Proof of Concept) code has been published on GitHub<\/strong> just days after the announcement, making the risk of active exploitation immediately elevated.<\/p>\n\n<p class=\"wp-block-paragraph\">The patch moves the <em>stale root<\/em> check to run <strong>after<\/strong> make_mmu_pages_available(). If the reclaim invalidates the current root, KVM now restarts fault handling with RET_PF_RETRY instead of continuing to map under an invalid root.<\/p>\n\n<h2 class=\"wp-block-heading\">Solution<\/h2>\n\n<p class=\"wp-block-paragraph\">Update the kernel to the fixed versions:<\/p>\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Branch<\/strong><\/td><td><strong>Fixed version<\/strong><\/td><\/tr><tr><td><strong>Mainline<\/strong><\/td><td>7.1.6 or 7.2-rc5<\/td><\/tr><tr><td><strong>Stable 6.18.x<\/strong><\/td><td>6.18.42<\/td><\/tr><tr><td><strong>Stable 6.12.x (LTS)<\/strong><\/td><td>6.12.101<\/td><\/tr><tr><td><strong>Stable 6.6.x (LTS)<\/strong><\/td><td>6.6.148<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<p class=\"wp-block-paragraph\">Kernel update in various distributions:<\/p>\n\n<p class=\"wp-block-paragraph\"># Debian \/ Ubuntu<br \/>apt update &amp;&amp; apt upgrade linux-image-$(uname -r)<br \/><br \/># RHEL \/ CentOS \/ AlmaLinux \/ Rocky<br \/>dnf update kernel<br \/><br \/># CloudLinux<br \/>yum update kernel<br \/><br \/># Arch Linux<br \/>pacman -Syu linux<br \/><br \/># Verify version after update<br \/>uname -r<\/p>\n\n<h2 class=\"wp-block-heading\">Mitigation<\/h2>\n\n<p class=\"wp-block-paragraph\">While planning the application of the kernel patch, you can follow these recommendations:<\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>Disable nested virtualization<\/strong> on all hosts where it is not strictly necessary. This is the most effective mitigation as it eliminates the main prerequisite of the attack:<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\"># QEMU\/KVM \u2014 disable nested virt per VM<br \/>-cpu ${CPU},vmx=off,svm=off<br \/><br \/># Or at the kernel module level<br \/>echo &#8220;options kvm_intel nested=0&#8221; &gt;&gt; \/etc\/modprobe.d\/kvm.conf<br \/>echo &#8220;options kvm_amd nested=0&#8221;   &gt;&gt; \/etc\/modprobe.d\/kvm.conf<br \/>modprobe -r kvm_intel &amp;&amp; modprobe kvm_intel<\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>Apply live patching<\/strong> with tools such as <strong>KSplice<\/strong> or <strong>kpatch<\/strong> as a first-aid measure while scheduling a reboot to update the kernel.<\/li>\n\n\n\n<li><strong>Audit which VMs have access to nested virtualization<\/strong> in the environment and restrict it exclusively to trusted guests.<\/li>\n\n\n\n<li><strong>In multi-tenant cloud environments:<\/strong> review the configuration of cpu_flags exposed to guests and remove vmx\/svm from untrusted third-party guests.<\/li>\n\n\n\n<li><strong>Monitor<\/strong> unusual access attempts to the KVM subsystem from within VMs.<\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\">\u00a0<\/h2>\n\n<h2 class=\"wp-block-heading\">Additional information:<\/h2>\n\n<ul class=\"wp-block-list\">\n<li>The<strong> <\/strong>Hacker News \u2014 Zapscape CVE-2026-64561: https:\/\/thehackernews.com\/2026\/08\/new-zapscape-kvm-flaw-could-let.html<\/li>\n\n\n\n<li>NVD \u2014 CVE-2026-64561: https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-64561<\/li>\n\n\n\n<li>Red Hat \u2014 CVE-2026-64561: https:\/\/access.redhat.com\/security\/cve\/cve-2026-64561<\/li>\n\n\n\n<li>CloudLinux \u2014 Analysis and mitigation: https:\/\/blog.cloudlinux.com\/zapscape-cve-2026-64561<\/li>\n\n\n\n<li>Debian Security Tracker: https:\/\/security-tracker.debian.org\/tracker\/CVE-2026-64561<\/li>\n\n\n\n<li>Hispasec \u2014 Technical analysis in Spanish: <a href=\"https:\/\/unaaldia.hispasec.com\">https:\/\/unaaldia.hispasec.com<\/a><\/li>\n\n\n\n<li>Upstream fix commit: 2abd5287f083 \u2014 linux\/kernel\/git\/torvalds\/linux<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=2abd5287f083\">https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=2abd5287f083<\/a><\/p>\n","protected":false},"featured_media":11672,"template":"","class_list":["post-12036","publicacion","type-publicacion","status-publish","has-post-thumbnail","hentry"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Affected product(s): Linux Kernel \u2014 KVM\/x86 Subsystem (Kernel-based Virtual Machine) Description A use-after-free vulnerability has been disclosed in the KVM\/x86 subsystem of the Linux kernel. It has been identified as CVE-2026-64561 with a CVSSv3.1 score of 7.0 \u2014 Important; the researcher named it Zapscape, The flaw allows an attacker with root privileges inside a guest\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Beacon Lab - CSIRT by Cybolt\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Alert 2026-86 Virtual Machine Escape with Host RCE in the Linux KVM Kernel (\u201cZapscape\u201d) - Beacon Lab\" \/>\n\t\t<meta property=\"og:description\" content=\"Affected product(s): Linux Kernel \u2014 KVM\/x86 Subsystem (Kernel-based Virtual Machine) Description A use-after-free vulnerability has been disclosed in the KVM\/x86 subsystem of the Linux kernel. It has been identified as CVE-2026-64561 with a CVSSv3.1 score of 7.0 \u2014 Important; the researcher named it Zapscape, The flaw allows an attacker with root privileges inside a guest\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/08\/kvm-linux-kernel.jpeg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/08\/kvm-linux-kernel.jpeg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"738\" \/>\n\t\t<meta property=\"og:image:height\" content=\"234\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-08-07T21:10:27+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-29T23:00:13+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@BeaconLabMX\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Alert 2026-86 Virtual Machine Escape with Host RCE in the Linux KVM Kernel (\u201cZapscape\u201d) - Beacon Lab\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Affected product(s): Linux Kernel \u2014 KVM\/x86 Subsystem (Kernel-based Virtual Machine) Description A use-after-free vulnerability has been disclosed in the KVM\/x86 subsystem of the Linux kernel. It has been identified as CVE-2026-64561 with a CVSSv3.1 score of 7.0 \u2014 Important; the researcher named it Zapscape, The flaw allows an attacker with root privileges inside a guest\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/08\/kvm-linux-kernel.jpeg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\\\/#listItem\",\"name\":\"Alert 2026-86 Virtual Machine Escape with Host RCE in the Linux KVM Kernel (&#8220;Zapscape&#8221;)\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\\\/#listItem\",\"position\":2,\"name\":\"Alert 2026-86 Virtual Machine Escape with Host RCE in the Linux KVM Kernel (&#8220;Zapscape&#8221;)\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"telephone\":\"+528007374357\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.mx\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/BeaconLab_V2-03.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/BeaconLabMX\",\"https:\\\/\\\/www.linkedin.com\\\/showcase\\\/beaconlabmx\"]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\\\/#webpage\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\\\/\",\"name\":\"Alert 2026-86 Virtual Machine Escape with Host RCE in the Linux KVM Kernel (\\u201cZapscape\\u201d) - Beacon Lab\",\"description\":\"Affected product(s): Linux Kernel \\u2014 KVM\\\/x86 Subsystem (Kernel-based Virtual Machine) Description A use-after-free vulnerability has been disclosed in the KVM\\\/x86 subsystem of the Linux kernel. It has been identified as CVE-2026-64561 with a CVSSv3.1 score of 7.0 \\u2014 Important; the researcher named it Zapscape, The flaw allows an attacker with root privileges inside a guest\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\\\/#breadcrumblist\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/kvm-linux-kernel.jpeg\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\\\/#mainImage\",\"width\":738,\"height\":234},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\\\/#mainImage\"},\"datePublished\":\"2026-08-07T15:10:27-06:00\",\"dateModified\":\"2026-09-29T17:00:13-06:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Alert 2026-86 Virtual Machine Escape with Host RCE in the Linux KVM Kernel (\u201cZapscape\u201d) - Beacon Lab","description":"Affected product(s): Linux Kernel \u2014 KVM\/x86 Subsystem (Kernel-based Virtual Machine) Description A use-after-free vulnerability has been disclosed in the KVM\/x86 subsystem of the Linux kernel. It has been identified as CVE-2026-64561 with a CVSSv3.1 score of 7.0 \u2014 Important; the researcher named it Zapscape, The flaw allows an attacker with root privileges inside a guest","canonical_url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","position":1,"name":"Home","item":"https:\/\/beaconlab.us\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\/#listItem","name":"Alert 2026-86 Virtual Machine Escape with Host RCE in the Linux KVM Kernel (&#8220;Zapscape&#8221;)"}},{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\/#listItem","position":2,"name":"Alert 2026-86 Virtual Machine Escape with Host RCE in the Linux KVM Kernel (&#8220;Zapscape&#8221;)","previousItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","name":"Home"}}]},{"@type":"Organization","@id":"https:\/\/beaconlab.us\/en\/#organization","name":"Beacon Lab","description":"CSIRT by Cybolt","url":"https:\/\/beaconlab.us\/en\/","telephone":"+528007374357","logo":{"@type":"ImageObject","url":"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\/#organizationLogo"},"image":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\/#organizationLogo"},"sameAs":["https:\/\/twitter.com\/BeaconLabMX","https:\/\/www.linkedin.com\/showcase\/beaconlabmx"]},{"@type":"WebPage","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\/#webpage","url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\/","name":"Alert 2026-86 Virtual Machine Escape with Host RCE in the Linux KVM Kernel (\u201cZapscape\u201d) - Beacon Lab","description":"Affected product(s): Linux Kernel \u2014 KVM\/x86 Subsystem (Kernel-based Virtual Machine) Description A use-after-free vulnerability has been disclosed in the KVM\/x86 subsystem of the Linux kernel. It has been identified as CVE-2026-64561 with a CVSSv3.1 score of 7.0 \u2014 Important; the researcher named it Zapscape, The flaw allows an attacker with root privileges inside a guest","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/beaconlab.us\/en\/#website"},"breadcrumb":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\/#breadcrumblist"},"image":{"@type":"ImageObject","url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/08\/kvm-linux-kernel.jpeg","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\/#mainImage","width":738,"height":234},"primaryImageOfPage":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\/#mainImage"},"datePublished":"2026-08-07T15:10:27-06:00","dateModified":"2026-09-29T17:00:13-06:00"},{"@type":"WebSite","@id":"https:\/\/beaconlab.us\/en\/#website","url":"https:\/\/beaconlab.us\/en\/","name":"Beacon Lab","description":"CSIRT by Cybolt","inLanguage":"en-US","publisher":{"@id":"https:\/\/beaconlab.us\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"Beacon Lab - CSIRT by Cybolt","og:type":"article","og:title":"Alert 2026-86 Virtual Machine Escape with Host RCE in the Linux KVM Kernel (\u201cZapscape\u201d) - Beacon Lab","og:description":"Affected product(s): Linux Kernel \u2014 KVM\/x86 Subsystem (Kernel-based Virtual Machine) Description A use-after-free vulnerability has been disclosed in the KVM\/x86 subsystem of the Linux kernel. It has been identified as CVE-2026-64561 with a CVSSv3.1 score of 7.0 \u2014 Important; the researcher named it Zapscape, The flaw allows an attacker with root privileges inside a guest","og:url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\/","og:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/08\/kvm-linux-kernel.jpeg","og:image:secure_url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/08\/kvm-linux-kernel.jpeg","og:image:width":738,"og:image:height":234,"article:published_time":"2026-08-07T21:10:27+00:00","article:modified_time":"2026-09-29T23:00:13+00:00","twitter:card":"summary_large_image","twitter:site":"@BeaconLabMX","twitter:title":"Alert 2026-86 Virtual Machine Escape with Host RCE in the Linux KVM Kernel (\u201cZapscape\u201d) - Beacon Lab","twitter:description":"Affected product(s): Linux Kernel \u2014 KVM\/x86 Subsystem (Kernel-based Virtual Machine) Description A use-after-free vulnerability has been disclosed in the KVM\/x86 subsystem of the Linux kernel. It has been identified as CVE-2026-64561 with a CVSSv3.1 score of 7.0 \u2014 Important; the researcher named it Zapscape, The flaw allows an attacker with root privileges inside a guest","twitter:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/08\/kvm-linux-kernel.jpeg"},"aioseo_meta_data":{"post_id":"12036","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-09-29 22:59:13","updated":"2026-09-29 23:00:13","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/beaconlab.us\/en\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAlert 2026-86 Virtual Machine Escape with Host RCE in the Linux KVM Kernel (\u201cZapscape\u201d)\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/beaconlab.us\/en\/"},{"label":"Alert 2026-86 Virtual Machine Escape with Host RCE in the Linux KVM Kernel (&#8220;Zapscape&#8221;)","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-86-virtual-machine-escape-with-host-rce-in-the-linux-kvm-kernel-zapscape\/"}],"_links":{"self":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/12036","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion"}],"about":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/types\/publicacion"}],"version-history":[{"count":1,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/12036\/revisions"}],"predecessor-version":[{"id":12037,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/12036\/revisions\/12037"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media\/11672"}],"wp:attachment":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media?parent=12036"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}