CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

CVE-2026-89775: Guest-to-Host Escape in KVM/arm64

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7535

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-89775: Guest-to-Host Escape in KVM/arm64

CVE-2026-89775 is a guest-to-host escape vulnerability in KVM/arm64 that affects systems with nested virtualization enabled. The flaw stems from a type truncation in the stage-1 walk level, causing size computation to return 0, which is then misinterpreted as a valid value by the VNCR pseudo-TLB invalidation path.

Why it matters: Virtualization administrators and cloud providers running KVM/arm64 with nested virtualization must patch to prevent guest virtual machines from escaping and accessing host kernel memory.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary