# Zapscape: KVM Guest-to-Host Escape Puts Nested Virtualization at Risk


## The Threat


A newly disclosed Linux kernel vulnerability called Zapscape gives an attacker with root access inside a guest virtual machine a credible path to executing code on the underlying host. The flaw lives in KVM's shadow memory management unit — the piece of code responsible for translating guest memory addresses when nested virtualization is active — and it enables a use-after-free condition that a determined attacker can turn into a full host compromise.


The mechanics are specific but the consequence is stark: the hypervisor boundary, which cloud infrastructure treats as a hard isolation guarantee, can be crossed. Researcher Hyunwoo Kim published a proof-of-concept on August 6, 2026 that creates a root-owned file named /Zapscape on the host from inside a guest. That's not a theoretical capability — it's a working demonstration of the escape chain.


The flaw traces back to a race in KVM's stale-root checking logic during shadow page fault handling. When a guest triggers a page fault, KVM may reclaim MMU pages and invalidate the shadow root that the fault-handling path is actively using. Because KVM only checks for staleness before making additional MMU pages available — not afterward — the fault path can continue under an invalidated root, creating child shadow pages that inherit the invalid state. Those orphaned pages get placed on KVM's active MMU page list, and later cleanup ends up attaching the same list link to two lists simultaneously before freeing the page. The result is a dangling list reference and a post-free write — the classic ingredient for exploitable corruption.


## Severity and Impact


| Field | Detail |

|-------|--------|

| CVE | CVE-2026-64561 |

| CVSS Score | 7.0 (Red Hat preliminary) |

| CVSS Vector | AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |

| Attack Complexity | High |

| Privileges Required | High (kernel/root inside L1 guest) |

| Scope | Changed (guest to host) |

| CWE | CWE-825 (Expired Pointer Dereference) |

| Exploit Status | Public PoC available; no in-the-wild exploitation reported |


The 7.0 score reflects the real-world bar: exploiting Zapscape requires kernel-level access within the guest, and on Intel hardware, the host must be exposing both EPT page-walk lengths 4 and 5 to the L1 guest. AMD systems have no equivalent hardware precondition, making them a slightly broader target surface.


## Affected Products


Linux Kernel (upstream)

  • Linux 5.9 through any release before the fixed stable versions
  • Fixed in: 6.6.148, 6.12.101, 6.18.42, 7.1.6, 7.2-rc5

  • Debian

  • Bullseye, Bookworm, Trixie, Forky — vulnerable as of August 6, 2026 (including security repos)
  • Sid — fixed at kernel version 7.1.6-1

  • Red Hat / RHEL

  • Status depends on vendor tracker; Red Hat notes packages frequently carry backported fixes without rebasing to a new upstream version string — do not rely on version numbers alone

  • Other distributions

  • Check your vendor's kernel tracker directly; package status does not map cleanly to upstream version strings

  • Scope condition (required for exploitation)

  • Host must expose nested virtualization to untrusted guests
  • Intel systems additionally require EPT page-walk length 4 and 5 exposed to the L1 guest
  • AMD nested SVM/NPT has no equivalent hardware gate

  • ## Mitigations


    Preferred: Update the kernel. Apply a patched stable kernel (6.6.148, 6.12.101, 6.18.42, 7.1.6, or 7.2-rc5) or a vendor package that backports commit 2abd5287f083, which moves the stale-root check to after MMU page reclaim rather than before it.


    If immediate patching is not possible:

  • Disable nested virtualization on hosts that expose it to untrusted or multi-tenant guests. This eliminates the attack surface entirely. The flaw is only reachable when an L1 guest can trigger nested page fault handling in the shadow MMU.
  • Enforce strict guest privilege separation. The exploit requires kernel/root inside the L1 guest. Hardened guest environments that prevent privilege escalation within the guest raise the effective bar.
  • Monitor for anomalous host filesystem writes originating from KVM paths — the PoC's canary behavior (writing /Zapscape on the host) gives defenders a concrete indicator of compromise to watch.
  • For cloud and VPS providers running nested virt for customer workloads: treat this as a priority patch, not a routine update cycle.

  • Red Hat's advisory and Debian's security tracker should be monitored for package availability, as backported fixes may appear before a full version rebase.


    ## References


  • [Linux kernel commit 2abd5287f083 (upstream fix)](https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/)
  • [Hyunwoo Kim's technical write-up and disclosure (August 6, 2026)](https://kernel.org)
  • [Red Hat CVE-2026-64561 advisory](https://access.redhat.com/security/cve/CVE-2026-64561)
  • [Debian security tracker — linux package](https://security-tracker.debian.org/tracker/CVE-2026-64561)
  • [National Vulnerability Database — CVE-2026-64561](https://nvd.nist.gov/vuln/detail/CVE-2026-64561)

  • ---


    ## HackWire Analysis


    Zapscape deserves close attention not because of what it does today but because of what it signals about where hypervisor security is heading. The immediate exploitation bar is legitimately high — guest root, specific hardware configuration on Intel, and enough host kernel internals knowledge to adapt the PoC to a live target. Kim himself says this isn't a weaponized exploit that "runs immediately" in cloud environments. But that framing can lull operators into misplaced comfort.


    The shadow MMU is not exotic code. It runs on every Linux KVM host that supports nested virtualization, and nested virt is no longer a niche feature. It's the mechanism that lets cloud providers offer nested environments to enterprise customers who want to run their own hypervisors — VMware, Hyper-V, or even KVM — on top of rented infrastructure. That architectural choice, which has become increasingly common over the last several years, is exactly the threat model Zapscape was designed to stress-test.


    The deeper issue is that use-after-free vulnerabilities in MMU management are structurally hard to eliminate. The shadow page tables exist because hardware-assisted translation still has gaps in certain nested configurations, and the bookkeeping required to keep those tables coherent under concurrent guest activity is notoriously subtle. This isn't the first KVM UAF and won't be the last.


    For defenders, the practical priority is simple: if you're running nested virtualization and exposing it to guests you don't fully control — including multi-tenant cloud workloads, CI environments, or developer sandboxes — patching isn't optional this cycle. The PoC is public, the primitive is documented, and the only real protection is the fixed kernel. Distro packages will lag; track your vendor's security tracker rather than assuming a recent install is clean.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)