By Korben
Publication Date: 2026-09-23 06:45:00
Flaws that let a virtual machine escape to the machine hosting it don’t grow on trees. And the one that just showed up is pretty impressive! A few days ago, researcher Hyunwoo Kim published CVE-2026-89775, a well-hidden “guest to host” escape in KVM (on ARM64 architectures). As a reminder, KVM is the virtualization component of the Linux kernel. And the CVSS score climbs all the way up to 9.3 out of 10! So yeah, this is serious business.
In practice, this flaw lets the VM read and write to the host’s kernel memory in 64-bit chunks at a time ^^, without even triggering the safeguard that’s supposed to hand control back. This is possible because of a simple size calculation that ends up at zero. As a result, the kernel treats that zero as a valid size, which lets it skip the memory cache invalidation.
Kim describes two ways to use it. The first is the
classic escape
where you can jump from a VM straight onto the host machine. This is basically the nightmare of anyone renting out ARM instances to multiple customers.
The second one is trickier and often overlooked. On distros like RHEL, the file /dev/kvm is writable by anyone. This lets a plain, unprivileged user use the flaw as an elevator straight to root, without even having to spin up a single VM.
So, are you affected??
There’s a good chance you aren’t, because on ARM64, nested virtualization isn’t a default mode of KVM. You have to enable it yourself at boot with kvm-arm.mode=nested, and be running a fairly recent chip.
But if…


