Zapscape - Guest to host escape in KVM/x86
Zapscape, a vulnerability (CVE-2026-64561) identified and reported by Hyunwoo Kim (@v4bel), allows a guest machine to bypass the host in a KVM/x86 environment and execute commands with root-level privileges on the host. This issue, a use-after-free vulnerability within the shadow MMU emulation of KVM/x86, specifically the recursive zap path when shadow pages are reclaimed, can be triggered with guest-side actions alone to compromise the host's kernel shadow page.
Zapscape poses a threat to KVM/x86 hosts that accept untrusted guests and permit nested virtualization, especially in multi-tenant x86 public clouds.
The vulnerability spans from f95eec9bed76 (2020-07-08) to 2abd5287f083 (2026-07-21). It occurs within the same shadow MMU but is a distinct vulnerability with a different root cause than Januscape. On Intel, it can only be triggered when both EPT page walk length 4 and 5 are accessible to L1. This is a crucial factor to consider when evaluating the affected hosts.
Zapscape is an in-kernel KVM issue, meaning it does not rely on QEMU's emulation and can affect large public clouds that utilize their own virtualization stack, even if guest-root access is not granted. In such cases, the exploit can be chained with a local privilege escalation vulnerability like Dirty Frag.
The provided PoC is structured for AMD and is recommended to be run under QEMU TCG for safe testing. It serves as demonstration code to reproduce the vulnerability and the full exploit chain on top of QEMU TCG. To be utilized in a real cloud environment, the L1 actions in the PoC must be incorporated into a guest kernel module and adapted to match the host kernel's kconfig.
This PoC is not intended as a weaponized exploit but to provide accurate information about the vulnerability. It should not be used on systems for which testing is unauthorized.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.