‹ BackHN Continuity

Thread

Zapscape (CVE-2026-64561): Guest-to-Host Escape in KVM/x86

61 points · 9 comments · john_strinlai

  1. minimaltom · · focus · HN ↗
    Oh yay another one lol. This one seems much more general than the prior one that needed nested page tables.

    Patch Thursday for cloud VM ppl lol

    1. tryauuum · · focus · HN ↗
      Doesn't this one need it as well? I see the shadow mmu
      1. minimaltom · · focus · HN ↗
        Right, but what x86 KVM setup is there in practice that doesnt present a mmu to its guest and hence keep its own track (shadow) of memory mappings?
        1. Veserv · · focus · HN ↗
          Shadow memory mappings are only needed when you do not have hardware virtualization or when doing nested virtualization.

          From the page: "it can threaten the guest-host isolation of KVM/x86 hosts that accept untrusted guests and expose nested virtualization"

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.