# Zapscape: KVM Guest-to-Host Escape Puts Nested Virtualization at Risk
## The Threat
A newly disclosed Linux kernel vulnerability called Zapscape gives an attacker with root access inside a guest virtual machine a credible path to executing code on the underlying host. The flaw lives in KVM's shadow memory management unit — the piece of code responsible for translating guest memory addresses when nested virtualization is active — and it enables a use-after-free condition that a determined attacker can turn into a full host compromise.
The mechanics are specific but the consequence is stark: the hypervisor boundary, which cloud infrastructure treats as a hard isolation guarantee, can be crossed. Researcher Hyunwoo Kim published a proof-of-concept on August 6, 2026 that creates a root-owned file named /Zapscape on the host from inside a guest. That's not a theoretical capability — it's a working demonstration of the escape chain.
The flaw traces back to a race in KVM's stale-root checking logic during shadow page fault handling. When a guest triggers a page fault, KVM may reclaim MMU pages and invalidate the shadow root that the fault-handling path is actively using. Because KVM only checks for staleness before making additional MMU pages available — not afterward — the fault path can continue under an invalidated root, creating child shadow pages that inherit the invalid state. Those orphaned pages get placed on KVM's active MMU page list, and later cleanup ends up attaching the same list link to two lists simultaneously before freeing the page. The result is a dangling list reference and a post-free write — the classic ingredient for exploitable corruption.
## Severity and Impact
| Field | Detail |
|-------|--------|
| CVE | CVE-2026-64561 |
| CVSS Score | 7.0 (Red Hat preliminary) |
| CVSS Vector | AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
| Attack Complexity | High |
| Privileges Required | High (kernel/root inside L1 guest) |
| Scope | Changed (guest to host) |
| CWE | CWE-825 (Expired Pointer Dereference) |
| Exploit Status | Public PoC available; no in-the-wild exploitation reported |
The 7.0 score reflects the real-world bar: exploiting Zapscape requires kernel-level access within the guest, and on Intel hardware, the host must be exposing both EPT page-walk lengths 4 and 5 to the L1 guest. AMD systems have no equivalent hardware precondition, making them a slightly broader target surface.
## Affected Products
Linux Kernel (upstream)
Debian
Red Hat / RHEL
Other distributions
Scope condition (required for exploitation)
## Mitigations
Preferred: Update the kernel. Apply a patched stable kernel (6.6.148, 6.12.101, 6.18.42, 7.1.6, or 7.2-rc5) or a vendor package that backports commit 2abd5287f083, which moves the stale-root check to after MMU page reclaim rather than before it.
If immediate patching is not possible:
/Zapscape on the host) gives defenders a concrete indicator of compromise to watch.Red Hat's advisory and Debian's security tracker should be monitored for package availability, as backported fixes may appear before a full version rebase.
## References
---
## HackWire Analysis
Zapscape deserves close attention not because of what it does today but because of what it signals about where hypervisor security is heading. The immediate exploitation bar is legitimately high — guest root, specific hardware configuration on Intel, and enough host kernel internals knowledge to adapt the PoC to a live target. Kim himself says this isn't a weaponized exploit that "runs immediately" in cloud environments. But that framing can lull operators into misplaced comfort.
The shadow MMU is not exotic code. It runs on every Linux KVM host that supports nested virtualization, and nested virt is no longer a niche feature. It's the mechanism that lets cloud providers offer nested environments to enterprise customers who want to run their own hypervisors — VMware, Hyper-V, or even KVM — on top of rented infrastructure. That architectural choice, which has become increasingly common over the last several years, is exactly the threat model Zapscape was designed to stress-test.
The deeper issue is that use-after-free vulnerabilities in MMU management are structurally hard to eliminate. The shadow page tables exist because hardware-assisted translation still has gaps in certain nested configurations, and the bookkeeping required to keep those tables coherent under concurrent guest activity is notoriously subtle. This isn't the first KVM UAF and won't be the last.
For defenders, the practical priority is simple: if you're running nested virtualization and exposing it to guests you don't fully control — including multi-tenant cloud workloads, CI environments, or developer sandboxes — patching isn't optional this cycle. The PoC is public, the primitive is documented, and the only real protection is the fixed kernel. Distro packages will lag; track your vendor's security tracker rather than assuming a recent install is clean.
— HackWire Editorial
---
## Related Coverage