CuraSec

Act active

CVE-2026-89775: Linux KVM ARM64 Guest-Escape via Use-After-Free

2026-09-22 15:30 UTC · The Hacker News · read the source ↗ #linux-kernel#virtualization#guest-escape
  • Engineer — Act: A public PoC on GitHub for a guest-to-host escape on ARM64 KVM hosts with nested virtualization enabled demands immediate attention: patch the Linux kernel to the fixed version and, where nested virtualization is not required, disable it now to remove the attack surface.
  • SOC/IR — Learn: No active exploitation is reported and EPSS is effectively zero, so there is no detection action to take today; however, understanding the KVM guest-escape technique is worth filing for future hunt hypothesis development should exploitation emerge.
  • Leader — Skip
  • Signals: CVE-2026-89775 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.