Zapscape (CVE-2026-64561): Guest-to-Host Escape in KVM/x86
- Security
- Infrastructure
- Cloud
- Open Source
The post points to a GitHub repository for “Zapscape,” described as CVE-2026-64561, a guest-to-host escape in KVM/x86. In plain terms, it is a virtualization isolation bug. A malicious guest VM could potentially cross the boundary into the host, which is the class of flaw cloud operators hate most because it threatens multi-tenant isolation.
If you run KVM-based infrastructure, check whether nested virtualization is enabled for untrusted tenants before treating this as a broad fleet emergency. If you buy cloud capacity, expect routine live migration or rolling maintenance rather than obvious outages while providers patch.
-
github.com
- Discuss on HN