Zapscape Linux Kernel Vulnerability Allows Privileged L1 Guest Code Escape

Unpatched Zapscape Linux kernel flaw enables L1 guest VMs to breach KVM isolation, exposing the host to malicious code execution

Researchers have identified a critical vulnerability in the Zapscape Linux kernel, which could allow an unprivileged attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute arbitrary code on the host.

The risk arises when nested virtualization is exposed to untrusted guests, potentially leading to unauthorized access and code injection.

The vulnerability, tracked as CVE-2026-64, has been assigned a CVSS score of 9.5, indicating a high level of severity and potential impact.

Experts warn that the flaw can be exploited by attackers with kernel privileges inside an L1 guest VM to breach KVM isolation and inject malicious code onto the host.

Due to the potential for widespread exploitation, it is essential for system administrators and developers to apply the necessary patches and updates as soon as possible.

As of March 10, 2023, the Zapscape Linux kernel vulnerability has not been officially addressed by the Zapscape project, and its impact is still being assessed.

More information on the vulnerability can be found on the Zapscape project's GitHub page, where a detailed report and proof-of-concept code are available for researchers and developers to review.

Source: The Hacker News