EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

Editorial source
Editorial OSINT source. The content is an indication to verify with independent institutional or technical sources before operational decisions.
EudorIA operational summary

What it means

Priority 45/100

Un bug nel kernel Linux KVM per ARM64 (CVE-2026-89775) permette a un guest di leggere e scrivere memoria del host. Il problema è presente in kernel 6.16 e risolve in 6.18.51, 7.2.5 e 7.3-rc1. L'attacco richiede nested virtualization abilitata, non attiva per default su ARM64. Non è sfruttato in rete, ma potrebbe interessare cloud provider.

Why it matters

Per PMI italiane che utilizzano virtualizzazione ARM64, il rischio è elevato se nested virtualization è abilitata. L'accesso al kernel host potrebbe portare a fuga di dati o controllo totale del sistema. La mancanza di patch in alcuni sistemi aumenta la vulnerabilità.

Potential operational benefits

  • Riduzione della superficie esposta
  • Prevenzione di fuga di dati sensibili
  • Miglioramento della sicurezza della virtualizzazione
  • Minimizzazione del rischio di attacchi locali
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementSegmentazione di reteFirewall NGFW / IPSMonitoraggio / SIEMMFA / Identità
AudienceITSOCCISO
Information centre

Translation in progress

The Hacker News

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.

Source
The Hacker News
Publishing entity
The Hacker News
Entity type
editorial osint
Area
Global
Original language
en · translation in preparation
Publication
22/09/2026 13:38
MITRE ATT&CK
T1562, T1486
CVE
CVE-2026-89775
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source