security1 publisher
CVE-2026-89775 leaves a freed host page mapped and writable inside ARM64 KVM guests
Hyunwoo Kim says a guest can use the bug to run code on the host, and he reports a local-root variant where /dev/kvm is world-openable. Both need ARM64 nested virtualization, a mode that is off by default.
Publishers:thehackernews.com
Reality
- Evidence58
- Adoption38
- Hype gap+8
- Incentives45
- Confidence60