Information has been disclosed about a vulnerability (CVE-2026-64561) in the KVM hypervisor that allows root access to the host environment while having root access in the guest system. This vulnerability can also be exploited for local privilege escalation with access to the /dev/kvm device (for example, in RHEL, such access is granted to all users). A prototype exploit is available for download. The issue has been assigned the codename Zapscape.
The vulnerability is caused by a use-after-free error in KVM hypervisor components running on the virtual machine to emulate the memory management unit (MMU) and translate addresses between the host and guest. On systems with Intel and AMD processors, the vulnerability occurs during the recursive deletion of shadow memory pages that occurs when MMU memory is freed (KVM recursively deletes the root shadow page, which remains in use during the MMU cleanup).
The issue is caused by a bug introduced six years ago and fixed a few days ago in kernel updates 7.1.6, 6.18.42, and 6.6.148. The status of vulnerability fixes in distributions can be assessed on these pages: Debian, Ubuntu, SUSE/openSUSE, RHEL, Gentoo, Arch, Fedora.
Source: opennet.ru
