Find notable cyber news and cases, enriched with sources, timelines, and signals.

Linux kernel ARM64 KVM guest-to-host escape security flaw (CVE-2026-89775)

Vulnerability
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-89775 is a Linux kernel KVM flaw on ARM64 that can let a guest read and write host kernel memory on systems with nested virtualization enabled. The issue creates a path to guest escape and possible host code execution on exposed hosts. It is fixed in Linux 6.18.51, 7.2.5, and 7.3-rc1.

Related Happenings

Linux kernel Dirty Frag local root escalation privilege-escalation flaw

Vulnerability
H score30 First: 08.05.2026 10:45 Last: 08.05.2026 10:45 Sources 1

About this happening: Dirty Frag is a newly disclosed Linux kernel zero-day that can give local attackers root privileges on most major Linux distributions. The flaw is anchored in the...

Linux kernel AppArmor confused deputy vulnerabilities CrackArmor security flaw

Vulnerability
H score56 First: 13.03.2026 10:18 Last: 13.03.2026 10:18 Sources 1

About this happening: Researchers disclosed CrackArmor, nine confused deputy flaws in the Linux kernel's AppArmor module that can let unprivileged users bypass protections, gain root*...

Timeline

  1. 22.09.2026 14:38 1 articles · 1h ago

    Hyunwoo Kim discloses CVE-2026-89775 ARM64 KVM guest escape

    Initial Disclosure

    Hyunwoo Kim disclosed CVE-2026-89775 on September 16 and described a flaw in Linux kernel KVM virtualization code for ARM64 with nested virtualization enabled that can leave freed host memory mapped and writable, letting a guest read and write host kernel memory, escape the guest, and run code on the host machine.

    Show sources
  2. 22.09.2026 14:38 2 articles · 1h ago

    Linux 6.18.51, 7.2.5, and 7.3-rc1 fix CVE-2026-89775

    Mitigation Patch Update

    As of September 22, upstream Linux fixed CVE-2026-89775 in Linux 6.18.51, 7.2.5, and 7.3-rc1, while downstream status varied across distributions, including Red Hat Enterprise Linux version 10 marked affected, versions 6 through 9 not affected, and Ubuntu 26.04 kernels described as vulnerable.

    Show sources