Critical Linux Kernel Vulnerability (CVE-2026-89775) Exposes ARM64 Virtualization to Host Escape Attacks
A newly disclosed Linux kernel vulnerability, CVE-2026-89775, allows attackers to escape an ARM64 virtual machine (VM) and gain unauthorized access to the underlying host system. The flaw affects KVM/arm64 environments with nested virtualization enabled, posing a severe risk to multi-tenant cloud infrastructure and systems permitting untrusted users to create VMs.
Security researcher Hyunwoo Kim identified the issue as a type truncation bug in the KVM/arm64 stage-1 page-table walk process. The vulnerability stems from an incorrect size calculation during pseudo-TLB invalidation, where a returned value of 0 intended to indicate an unknown memory size is misinterpreted as a valid range. This causes the invalidation operation to be skipped, leaving stale memory access mappings exposed to malicious guests.
Exploitation enables a guest VM to retain read/write access to freed host memory pages at fixed kernel addresses, bypassing traps or VM exits. Attackers could then manipulate host memory directly, compromising the isolation between guest and host systems. The flaw is particularly critical in public-cloud ARM64 deployments, where an attacker with nested virtualization access could escape a guest VM to the host, breaching tenant isolation.
Additionally, the vulnerability introduces a local privilege-escalation risk on systems where /dev/kvm is configured with world-writable permissions (0666), as seen in some Red Hat Enterprise Linux setups. An unprivileged local user could exploit the flaw to gain root privileges on the host.
The issue was introduced in Linux kernel commit 7270cc9157f47 (May 14, 2025) and patched upstream in commit 8053393680d4 (August 6, 2026). Administrators are advised to update to a patched kernel release as distributions make fixes available. Until then, disabling nested virtualization where unnecessary can mitigate exposure. Cloud providers should prioritize patching shared infrastructure, restrict tenant access to nested virtualization, and audit /dev/kvm permissions to limit local attack vectors. The Linux mainline kernel now includes the fix.
Source: https://cybersecuritynews.com/linux-kvm-arm64-vulnerability/
Kernel Foundation - Master Linux Kernel & LDD cybersecurity rating report: https://www.rankiteo.com/company/linux-kernel-foundation
"id": "LIN1790087374",
"linkid": "linux-kernel-foundation",
"type": "Vulnerability",
"date": "5/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Multi-tenant cloud providers, '
'enterprises using ARM64 '
'virtualization',
'industry': 'Technology/Cloud Computing',
'location': 'Global',
'name': 'Linux Kernel (ARM64 KVM environments)',
'type': 'Software/Operating System'},
{'customers_affected': 'Users with /dev/kvm configured '
'as world-writable (0666)',
'industry': 'Technology',
'location': 'Global',
'name': 'Red Hat Enterprise Linux',
'type': 'Operating System Distribution'}],
'attack_vector': 'Virtual Machine Escape',
'customer_advisories': 'Users of ARM64 virtualization environments should '
'update their systems and disable nested '
'virtualization if unnecessary.',
'data_breach': {'sensitivity_of_data': 'High (if sensitive data is accessed '
'post-exploitation)'},
'description': 'A newly disclosed Linux kernel vulnerability, CVE-2026-89775, '
'allows attackers to escape an ARM64 virtual machine (VM) and '
'gain unauthorized access to the underlying host system. The '
'flaw affects KVM/arm64 environments with nested '
'virtualization enabled, posing a severe risk to multi-tenant '
'cloud infrastructure and systems permitting untrusted users '
'to create VMs. The vulnerability stems from a type truncation '
'bug in the KVM/arm64 stage-1 page-table walk process, leading '
'to stale memory access mappings exposed to malicious guests. '
'Exploitation enables a guest VM to retain read/write access '
'to freed host memory pages, compromising isolation between '
'guest and host systems.',
'impact': {'brand_reputation_impact': 'Potential reputational damage for '
'cloud providers and Linux '
'distributions',
'identity_theft_risk': 'High if sensitive data is accessed '
'post-exploitation',
'legal_liabilities': 'Potential regulatory violations for '
'non-compliance with data protection laws',
'operational_impact': 'Compromised host-guest isolation, potential '
'unauthorized host access',
'payment_information_risk': 'High if payment data is stored in '
'compromised systems',
'systems_affected': 'ARM64 virtualization environments (KVM/arm64 '
'with nested virtualization enabled)'},
'investigation_status': 'Patched (upstream fix available)',
'lessons_learned': 'Importance of timely patching for virtualization '
'vulnerabilities; need for stricter permissions on '
'/dev/kvm; risks of nested virtualization in multi-tenant '
'environments.',
'post_incident_analysis': {'corrective_actions': 'Patch applied to fix the '
'size calculation bug; '
'additional hardening of '
'/dev/kvm permissions '
'recommended.',
'root_causes': 'Type truncation bug in KVM/arm64 '
'stage-1 page-table walk process '
'leading to incorrect size '
'calculation during pseudo-TLB '
'invalidation.'},
'recommendations': ['Update to the latest patched Linux kernel release '
'(commit 8053393680d4).',
'Disable nested virtualization where not required.',
'Audit and restrict /dev/kvm permissions to prevent local '
'privilege escalation.',
'Cloud providers should prioritize patching shared '
'infrastructure and restrict tenant access to nested '
'virtualization.',
'Monitor for signs of exploitation in ARM64 '
'virtualization environments.'],
'references': [{'source': 'Linux Kernel Commit (Patch)',
'url': 'https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8053393680d4'},
{'source': 'Linux Kernel Commit (Vulnerability Introduction)',
'url': 'https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7270cc9157f47'},
{'source': 'Security Researcher (Hyunwoo Kim)'}],
'response': {'containment_measures': 'Disable nested virtualization where '
'unnecessary; audit /dev/kvm permissions',
'remediation_measures': 'Update to a patched kernel release '
'(commit 8053393680d4)'},
'stakeholder_advisories': 'Cloud providers and enterprises using ARM64 '
'virtualization should apply patches immediately '
'and review nested virtualization configurations.',
'title': 'Critical Linux Kernel Vulnerability (CVE-2026-89775) Exposes ARM64 '
'Virtualization to Host Escape Attacks',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': 'CVE-2026-89775'}