Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Binance Takes $100M Stake in Circle Under Five-Year USDC Promotion Deal

    September 22, 2026

    An Epic View of the Seasons

    September 22, 2026

    Remote operations center for unmanned survey operations opens in Singapore

    September 22, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Binance Takes $100M Stake in Circle Under Five-Year USDC Promotion Deal
    • An Epic View of the Seasons
    • Remote operations center for unmanned survey operations opens in Singapore
    • Japan’s New CIA Could Be Takaichi’s Trump Card
    • Did Trump’s kindness ‘ruin’ Secret Service agent? Don’t fall for tall tale
    • Hundreds flee homes in Far North Cameroon after armed group raid kills 15 | Conflict News
    • OpenAI’s George Osborne says datacentre nimbys holding back Britain | George Osborne
    • Singapore’s Nexstrom wants to bring 2D semiconductors to chip fabs
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 22
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 22, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalSep 22, 2026Vulnerability / Virtualization

    A new flaw in the Linux kernel’s KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled.

    The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.

    The affected code is part of the mainline Linux kernel for ARM64, and it is fixed in Linux 6.18.51, 7.2.5, and 7.3-rc1.

    Nested virtualization allows a guest to run its own hypervisor, enabling it to host virtual machines. On ARM64, it is off by default. It is an experimental boot-time mode that needs Armv8.4 hardware with a feature called FEAT_NV2, so a plain ARM64 KVM host that never turns it on is outside the reported attack path.

    The flaw sits in the part of KVM that handles nested virtualization on ARM64. When a guest arranges its memory in a certain way, a size calculation comes out as zero, and a step that should clear stale entries from the processor’s address cache, a TLB invalidation, is skipped.

    A page of host memory that has been freed then stays mapped and writable, and the guest can read and write it 64 bits at a time, with no hardware trap to hand control back to the host.

    Hyunwoo Kim, the security researcher who reported the flaw and disclosed it on September 16, says a guest can use this to escape to the host, breaking out of its own virtual machine to run code on the underlying machine. No exploit code has been published, and there is no sign the flaw has been used in an attack.

    Cybersecurity

    The kernel’s own record lists the affected code as present from Linux 6.16. But the author tagged the fix against a later change, and the maintainer who reviewed and tested it said the “missed invalidation only starts at v6.17.” By that account, a host on 6.16 carries the code but not the behavior an attacker needs.

    There is a second way to abuse the flaw. On systems where any user can open /dev/kvm, the device a program uses to create a virtual machine, a local user could build a guest and use the same bug to gain root, Kim says.

    He points to Red Hat Enterprise Linux, where that device is open to all users by default. Red Hat lists its version 10 kernel as affected and versions 6 through 9 as not affected. This path still needs the host to have nested virtualization enabled.

    Which Kernels Are Fixed

    Upstream, the flaw is fixed in Linux 6.18.51, 7.2.5, and 7.3-rc1. Distributions are shipping the fix on their own schedules, and status differs by release.

    Kernel or distribution Status as of September 22
    Mainline Linux Fixed in 6.18.51, 7.2.5, and 7.3-rc1

    Red Hat Enterprise Linux
    Version 10 kernel affected; versions 6 through 9 not affected

    Ubuntu
    26.04, including its AWS, Azure, and GCP kernels, vulnerable; 24.04 LTS general kernel not affected, though its newer hardware-enablement kernels (6.17, 7.0) are vulnerable

    Amazon Linux
    AL2023 kernel6.18 package: fix pending; other Amazon Linux kernels not affected

    Debian
    bookworm and trixie not affected (code not present); sid fixed in 7.2.6-1; forky vulnerable

    For hosts that cannot yet be patched, Red Hat says no mitigation meets its criteria for a workaround. The one certain thing is scope: the attack only targets hosts with nested virtualization enabled, which is not the default on ARM64.

    Vendors score the flaw from 7.8 to 9.3 out of 10. They agree the impact is high and the attack is local, meaning it cannot be launched over a network. The spread reflects how difficult each vendor thinks the flaw is to exploit, and Ubuntu, which shows the 9.3 figure, sets its own priority to medium.

    Cybersecurity

    As of September 22, the flaw was not in the U.S. CISA catalog of exploited vulnerabilities, and its predicted exploitation score was below 1%.

    The disclosure raises the question of whether cloud tenants could use the flaw to break into a provider’s machines. On the largest providers, the configuration it needs is not on offer: Amazon Web Services lists only Intel-based instances for nested virtualization, and Google Cloud excludes its ARM virtual machines from it.

    That is not a clean bill of health for those platforms, but the specific path this flaw takes is not exposed in their standard ARM offerings.

    CVE-2026-89775 is the fourth KVM guest-to-host escape Kim has disclosed this year. Two were in the x86 version of KVM: Januscape in July and Zapscape in August. The one it most resembles is ITScape, an ARM64 KVM escape he published in June, which he called the first such escape shown publicly on ARM64.

    access ARM64 Flaw Guests Host Kernel KVM Linux memory ReadWrite
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    DORA Year Two: Can Your SOC Actually See the Attack?

    Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

    The cyber AI parity window now has a deadline

    Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme

    One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

    CrowdSec Confirms Source Code Stolen in Supply Chain Attack

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Binance Takes $100M Stake in Circle Under Five-Year USDC Promotion Deal

    September 22, 2026

    An Epic View of the Seasons

    September 22, 2026

    Remote operations center for unmanned survey operations opens in Singapore

    September 22, 2026

    Japan’s New CIA Could Be Takaichi’s Trump Card

    September 22, 2026
    Latest Posts

    COLDCARD security audit phishing attack installs remote access tool

    August 5, 2026

    Reddit aims to make ‘karma’ less important for first-time posters with shift to AI moderation tools

    August 5, 2026

    Right turn on green: is the Telegraph changing its tune on the climate? | Daily Telegraph

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Binance Takes $100M Stake in Circle Under Five-Year USDC Promotion Deal

    September 22, 2026

    An Epic View of the Seasons

    September 22, 2026

    Remote operations center for unmanned survey operations opens in Singapore

    September 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.