Critical Linux KVM Flaw Lets Attackers Escape Virtual Machines and Gain Root Access
Brief
A critical security vulnerability in Linux’s Kernel-based Virtual Machine (KVM) subsystem could allow attackers to break out of affected virtual machines, access the underlying host, and potentially gain root privileges.
Tracked as CVE-2026-89775, the flaw affects KVM on ARM64 systems when nested virtualization is enabled. Security researcher Hyunwoo Kim disclosed the issue after an embargo coordinated through the Linux distribution security process expired.
The vulnerability is especially significant for multi-tenant cloud environments, where an attacker with access to a guest virtual machine may be able to compromise the host system that runs it.
Critical Linux KVM Flaw
From there, the attacker could potentially access other workloads, virtual machines, and sensitive cloud infrastructure hosted on the same physical server.
