New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
- ID
- 27202
- Status
- summarized
- Published
- 22 Sep 2026, 7:38 PM
- Fetched
- 22 Sep 2026, 8:16 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/new-linux-kernel-flaw-gives-arm64-kvm.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 22 Sep 2026, 8:20 PM
- Tags
- Audience
- developersdatabase_learners
What happened
A Linux kernel KVM flaw (CVE-2026-89775) on ARM64 lets a guest VM read and write freed host kernel memory, enabling VM escape to run code on the host. The bug only affects hosts with experimental nested virtualization enabled (off by default, requires Armv8.4 FEAT_NV2), and is fixed in Linux 6.18.51, 7.2.5, and 7.3-rc1. A second abuse path exists on systems where /dev/kvm is world-accessible (e.g., RHEL by default), allowing a local unprivileged user to gain root.
Why it matters
If you run ARM64 KVM hosts (e.g., AWS Graviton, Ampere) on kernel 6.17+ with nested virtualization turned on, patch to 6.18.51+ or 7.2.5+ immediately. If you run RHEL or any distro where /dev/kvm is open to all users, restrict that device permission now regardless of architecture, since the local privilege escalation path doesn't require nested virt.
Discussion angle
How many Malaysian cloud and infra teams are actually running ARM64 KVM with nested virtualization versus x86, and whether the /dev/kvm permission default on RHEL is a sleeper local privesc risk worth auditing across their server fleet.