THREATOPS
THREAT OPSThreat News › CVE-2026-89775: Guest-to-Host Escape in KVM/arm64

CVE-2026-89775: Guest-to-Host Escape in KVM/arm64

medoss_secPublished 2026-09-16

<p>Posted by Hyunwoo Kim on Sep 16</p>Hi,<br /> <br /> The embargo agreed with the maintainers of<br /> linux-distros () vs openwall org has expired, so I am posting this report.<br /> <br /> CVE-2026-89775 is a guest-to-host escape in KVM/arm64 on hosts where<br /> nested virtualization is enabled.<br /> <br /> The root cause is a type truncation of the stage-1 walk level, which<br /> makes the s

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/811