Zapscape: A New KVM Escape Lets Guests Take Over the Host
Zapscape (CVE-2026-64561)

Security researcher Hyunwoo Kim (@v4bel) has published Zapscape (CVE-2026-64561), a use-after-free vulnerability in KVM/x86's shadow MMU that allows a guest to escape to the host and execute code with kernel privileges. The bug, triggered solely by guest actions, affects Linux kernels from 2020 to 2026 and threatens multi-tenant clouds exposing nested virtualization. The PoC runs under QEMU TCG and demonstrates full compromise, creating a root-owned file on the host. The disclosure follows an embargo agreed with linux-distros.
Winter is coming.