Information has been revealed about the vulnerability (CVE-2026-64561) in the KVM hypervisor, which allows gaining root-level access to the host environment if root privileges are already available in the guest system. This issue can also be used for local privilege escalation when having access to the device /dev/kvm (for example, in RHEL, such access is granted to all users). A prototype exploit is available for download. The issue has been codenamed Zapscape.
The vulnerability is caused by use-after-free memory access in the hypervisor components KVM, executed on the virtual machine side to emulate the memory management unit (MMU) and translate addresses between the host and the guest system. The vulnerability manifests itself on systems with Intel and AMD processors during the recursive deletion of shadow memory pages, which occurs when freeing MMU memory (KVM recursively deletes the root shadow page, which continues to be used during MMU cleanup).
The issue was caused by a mistake made 6 years ago, which has been fixed just a few days ago in kernel updates 7.1.6, 6.18.42, and 6.6.148. The status of vulnerability fixes in distributions can be evaluated on the following pages: Debian, Ubuntu, SUSE/openSUSE, RHEL, Gentoo, Arch, Fedora.
Source: opennet.ru
