# Critical Vulnerability in Linux KVM/arm64 Allows Virtual Machine Escape

*Published September 23, 2026*
*Source: [https://cybersecuritynews.com/linux-kvm-arm64-vulnerability/](https://cybersecuritynews.com/linux-kvm-arm64-vulnerability/)*

## Executive Summary

The CVE-2026-89775 vulnerability in KVM/arm64 environments allows attackers to escape virtual machines and access host systems, posing a threat to multi-tenant cloud infrastructures. Organizations should swiftly apply kernel patches and evaluate the need for nested virtualization to mitigate risks.

## Article

A critical vulnerability identified as CVE-2026-89775 in the Linux kernel's KVM/arm64 component poses a significant threat to systems utilizing nested virtualization. This flaw could allow attackers to bypass the security boundaries of ARM64 virtual machines and gain access to the host system. The vulnerability is particularly concerning for multi-tenant cloud environments, where untrusted users may have the ability to create virtual machines.

Security researcher Hyunwoo Kim discovered that the root of the problem lies in the type truncation issue within the KVM/arm64 stage-1 page-table walk process. This error affects how the kernel calculates the size of memory that needs invalidation from the virtual CPU's pseudo Translation Lookaside Buffer, or pseudo-TLB. Normally, KVM would invalidate outdated memory references after changes in memory mappings to prevent unauthorized access to released or reassigned memory. However, in this case, the faulty code path mistakenly interprets an invalidation size of zero as legitimate, leading to skipped invalidation operations and leaving stale memory access information vulnerable.

For cloud providers and organizations using ARM64 infrastructure, this vulnerability is particularly threatening. An attacker with the ability to initiate nested virtualization might transition from the guest to the host system, thereby breaching the isolation that protects individual virtual machines. Furthermore, the vulnerability could allow local privilege escalation if certain distributions, like Red Hat Enterprise Linux, expose /dev/kvm with overly permissive settings. The flaw originated in a kernel update from May 2025 and was resolved in an upstream fix by August 2026.

Administrators are urged to update their systems with the latest kernel patches offered by their distribution vendors. It is also advisable to assess the necessity of nested virtualization and disable it if not essential, reducing potential exposure until patches are fully deployed. Cloud service providers should act quickly to address this vulnerability by patching shared infrastructure and reviewing tenant permissions for nested virtualization access.
