New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
What it means
Un bug nel kernel Linux KVM per ARM64 (CVE-2026-89775) permette a un guest di leggere e scrivere memoria del host. Il problema è presente in kernel 6.16 e risolve in 6.18.51, 7.2.5 e 7.3-rc1. L'attacco richiede nested virtualization abilitata, non attiva per default su ARM64. Non è sfruttato in rete, ma potrebbe interessare cloud provider.
Why it matters
Per PMI italiane che utilizzano virtualizzazione ARM64, il rischio è elevato se nested virtualization è abilitata. L'accesso al kernel host potrebbe portare a fuga di dati o controllo totale del sistema. La mancanza di patch in alcuni sistemi aumenta la vulnerabilità.
Recommended actions
- Applicare patch Linux 6.18.51, 7.2.5 o 7.3-rc1
- Disabilitare nested virtualization se non necessario
- Limitare accesso a /dev/kvm solo agli utenti autorizzati
- Verificare le versioni dei kernel utilizzati in cloud e on-premise
- Monitorare accessi anomali al kernel host
- Eseguire audit di configurazione di virtualizzazione
- Aggiornare sistemi operativi e distribuzioni
Potential operational benefits
- Riduzione della superficie esposta
- Prevenzione di fuga di dati sensibili
- Miglioramento della sicurezza della virtualizzazione
- Minimizzazione del rischio di attacchi locali
Translation in progress
The official content is available in the original language. The Italian version will be published once automated checks are complete.
Text acquired from the source
A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.
- Source
- The Hacker News
- Publishing entity
- The Hacker News
- Entity type
- editorial osint
- Area
- Global
- Original language
- en · translation in preparation
- Publication
- 22/09/2026 13:38
- MITRE ATT&CK
- T1562, T1486
- CVE
- CVE-2026-89775
Affected products and versions
The collector will check NVD and the available official vendor advisories.