Zapscape: Critical KVM/x86 Guest-to-Host Escape Vulnerability Disclosed
cyb3rops · x · 2026-08-07
Security researcher Hyunwoo Kim (@v4bel) disclosed Zapscape (CVE-2026-64561), a high-severity guest-to-host escape vulnerability in KVM/x86.
- Technical Root Cause: It is a use-after-free (UAF) bug in the shadow MMU emulation, specifically within the recursive ZAP path triggered when reclaiming shadow pages.
- Impact: An attacker can execute guest-side actions to corrupt the host kernel's shadow page, escaping to the host with kernel (root) privileges. This severely threatens guest-host isolation in multi-tenant x86 public clouds that accept untrusted guests and expose nested virtualization.
- Recommendation: Distinct from the previously disclosed Januscape, vulnerable systems should apply patches immediately.
Following the end of the agreed embargo, the researcher published the technical details and a Proof of Concept (PoC).
More from Infra
- Handling 9B Daily Requests: Cloudflare Migrates cdnjs to Its Developer Platform — JeremyCMorgan · 2026-08-07
- Nvidia RTX Pro 6K Spot Instances Get Scarce and Pricier for AI Devs — blelbach · 2026-08-07
- Running MiniMax H3 Video Generation on RTX 4080 Laptop Takes Nearly an Hour — Last-Pie8057 · 2026-08-07
- Cloudflare Hailed as the Next Nvidia, Stock Surges 16% After-Hours — xiaohu · 2026-08-07
- Breaking 200 tok/s: Dynamic Requant Boosts Local LLM Inference Speed — gajesh · 2026-08-07
- Google Raises AI Spending Forecast to $205B, Making Wall Street Nervous — emmanuelvivier · 2026-08-07