Zapscape (CVE-2026-64561): Guest-to-Host Escape in KVM/x86
Posted by john_strinlai 13 hours ago
Comments
Comment by eqvinox 1 hour ago
(To disable nested virtualization on a per-VM basis. Only against exploitation from within that specific VM, obviously does nothing against users with access to /dev/kvm on the host.)
[That did work around Januscape: https://news.ycombinator.com/item?id=48815819]
Comment by minimaltom 12 hours ago
Patch Thursday for cloud VM ppl lol
Comment by esjeon 4 hours ago
Nested virtualization is rather a niche feature, and, tbh, considering that shadow MMU is highly complicated legacy code (i.e. outside of the main happy path) and has been source of critical vul'n, I would avoid nested virtualization on KVM.
Comment by metadat 12 hours ago
Comment by cudder 12 hours ago
You can also use ksplice to live patch the vulnerable kernels as a first aid. I'm not an expert but I think there are some limits to what you can accomplish with it. Also guessing that the embargo period allows the big names to roll the patches out gradually enough that you won't see any panic shutdowns.
Comment by minimaltom 10 hours ago
Comment by tryauuum 10 hours ago
Comment by minimaltom 10 hours ago
Comment by Veserv 8 hours ago
From the page: "it can threaten the guest-host isolation of KVM/x86 hosts that accept untrusted guests and expose nested virtualization"
That is not to say that it is not a serious vulnerability though.
Comment by rvz 13 hours ago
Comment by inigyou 11 hours ago
(This comment is a reference to https://youtu.be/v1Mfirg2-Z8