THE report details a critical KVM escape vulnerability named Zapscape, identified as CVE-2026-64561, which allows an attacker to break out from a guest environment to the host system, gaining kernel root privileges. The vulnerability stems from a use-after-free error in the KVM shadow MMU that requires nested virtualization. No confirmed exploitation has been reported as of yet, but proof-of-concept exploit code is publicly available. Patch updates have been issued to address the flaw.
Users are urged to apply the latest kernel updates promptly due to the potential severe consequences, which include the ability to crash the host or execute root-level commands across all guest systems.