The images in this article were generated with artificial intelligence. How we publish
Zapscape is the label that received a critical vulnerability detected in the Linux kernel KVM subsystem that manages the "Shadow" MMU for memory translation in nested virtualization environments. The failure, traced as CVE-2026-64561, allows an attacker who already has kernel privileges within a virtual L1 machine (i.e. normally root in that VM) to escape from KVM isolation and run code with host privileges. Although the vector requires a context of high privileges within the L1 and specific conditions in the CPU, the potential impact on environments that expose the nested virtualization to unreliable guests is significant: a malicious guest could compromise the host and, by extension, other VMs and workloads on that host.
Technically, vulnerability is a problem of order in the testing of obsolete roots (stale-root) within the bookkeeping of Shadow-MMU that can produce a use-after-free. During the handling of a page fault caused by the guest, KVM can claim MMU pages and invalidate the shadow@-@ MMU root that is still being used in the path of handling the lack. As the route does not re-check that root, KVM can continue to create daughter pages under an invalid root, leading finally to hanging links and post-liberation scriptures. Researcher Hyunwoo Kim published a technical demonstration and a public proof-of-concept that shows how, from this primitive, it is possible to run a complete chain of exploitation capable of creating a file in the host (e.g. / Zapscape) owned by the host root.

There are specific conditions for the attack to be exploitable: in addition to the usual requirement of kernel privileges within L1, in Intel systems it is necessary to expose to the guest L1 the length of Page-walk of EFA both 4 and 5; AMD does not require that additional condition and Kim's public PoC is addressed to SVM / NPT in AMD on Linux 7.1.3. It is important to stress that QEMU is not the vulnerable component: the failure lives in KVM's in- kernel code and can be triggered independently of the emulator; Kim even recommends using QEMU TCG for safe PoC tests because QEMU itself is not the exploitable surface.
The patch panorama is already clear: the upstream arrangement was merged (commit 2abd5287f083) and moves the stale-root check for after making _ mmu _ pages _ available (), causing, if the claim invalidated the current root, KVM to restart the failure with RET _ PF _ RETRY rather than continuing on an invalid root. The NVD lists kernel from 5.9 onwards as affected to stable parcheed versions; the versions with the upstream arrangement include 6.6.148, 6.12.101, 6.18.42 and 7.1.6. Managers should also review their distributions' notices because many distributors (e.g. Red Hat) apply backport patches within packages with numbers other than upstream. Official follow-up is available at the NVD and the commit in the kernel repository: NVD - CVE-2026-64561 and commit 2Abd5287f083 on git.kernel.
In terms of real risk and operational mitigation: Kim clarifies that the PoC is not immediate "cloud-ready weapons"; an explosion in production would require carrying L1 actions to a kernel module in the guest and adapting the operation to the host kernel configuration and its memory backend. However, the existence of public evidence requires rapid action. Red Hat issued a preliminary CVSS 7.0 rating and classified the problem as CWE-825 (atoned pointer dereference), which highlights the severity and possibility of climbing to control of the host.
If you manage KVM-based infrastructure and especially if you expose nested virtualization or provide VMs "capable of nesting" to customers or users, the immediate recommended actions are: apply the official patches or packages of your distributor that include the correction, or if it is not possible to park immediately, disable the exposure of nested virtualization to unreliable guests. In addition, you have heard which guests have kernel privileges or access to hardware that allows to activate operating conditions, and minimizes the distribution of virtualization capabilities in multi-tenant environments. Check the security trackers of your distribution because the status and version number may vary if the supplier has backloaded the fix.

For internal response and research teams wishing to reproduce or analyse the problem, Kim's public PoC is available with its technical analysis; using QEMU TCG for testing reduces the risk of accidental damage by not relying on hardware acceleration. Do not use PoC tests in production environments or on shared hosts without strict isolation. The links of the researcher and the upstream notice allow you to understand the technique and verify the patch applied in the official kernel tree.
Zapscape is, in context, part of a series of recent KVM discoveries that include previous failures such as Januscape (CVE-2026-53359) and ITScape (CVE-2026-46316), which evidence that the complexity of the Shadow-MMU code and nested virtualization remain a critical surface. The operational lesson is to prioritize kernel patches in virtualization hosts, reduce the exposure of advanced features to unreliable guests and maintain strict privilege policies within the VMs. For specific confirmations and remediation guides to your distribution, see also your supplier's security pages and launch notes: for example, Red Hat pages on CVE and kernel repositories of your distributions.
Sources and references to follow the answer: the official CVE record in the NVD, the kernel commit to the patch and the security pages of distributors such as Red Hat. Check these resources to verify that your hosts are in parched versions or that your packages include the corresponding backport before considering a safe environment against CVE-2026-64561.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...