Fetching from the wire…
Public story · 2026-08-07 · high
CVE-2026-64561 spans kernels from July 2020 to July 2026 and also escalates locally wherever /dev/kvm is world-writable.
Why now: Kim's exploit went public August 6, the same day the oss-security embargo on the bug lifted.
Security researcher Hyunwoo Kim published a working exploit for a KVM guest-to-host escape on August 6, after an oss-security embargo lifted.
The bug, tracked as CVE-2026-64561, lets code running inside an affected guest reach root on the host machine. It also works as local privilege escalation wherever /dev/kvm is left world-writable. That's the condition behind plenty of KVM-backed sandboxes and multi-tenant CI runners built to run untrusted or agent-generated code.
Kim published the proof-of-concept as Zapscape on GitHub. The flaw is a use-after-free in KVM/x86's recursive zap path during shadow page table reclamation. It's triggerable entirely from guest-side actions.
His writeup traces the affected window to two commits: f95eec9bed76, merged July 8, 2020, and the fix at 2abd5287f083, landed July 21, 2026. Just over six years of shipped kernels carried the bug.
The real risk isn't cloud hypervisors. It's the self-hosted KVM sandboxes running agent and CI workloads. Nobody's tracking six years of kernel drift there, or auditing /dev/kvm permissions, until a working exploit shows up on GitHub.
The exploit went public the same day the oss-security embargo on it lifted, August 6.
Each link below shares sources, entities, or timing with this story.
Shared entities / Same source domain / Shared topic
Both cover August, July; reported by the same outlet (github.com); overlapping topics (action, august, during, july).
Shared entities / Same source domain / Shared topic / Earlier coverage
Both cover August, July; reported by the same outlet (github.com); overlapping topics (agent, code, commit).
Shared entities / Shared topic / Earlier coverage / Tension
Both cover August, July; overlapping topics (agent, code, commit); earlier August coverage from 2026-08-04.
Shared entities / Shared topic / Earlier coverage
Both cover August, July; overlapping topics (action, agent, during, july); earlier August coverage from 2026-08-05.
Both cover August, July; overlapping topics (agent, august, july, through); earlier August coverage from 2026-07-10.
Shared entity: July / Same source domain / Shared topic / Earlier coverage / Tension
Both cover July; reported by the same outlet (github.com); overlapping topics (action, agent, july).
Shared entity: July / Same source domain / Shared topic / Earlier coverage
Both cover July; reported by the same outlet (github.com); overlapping topics (agent, code, commit, july).
Shared entities / Shared topic / Earlier coverage
Both cover August, July; overlapping topics (agent, august, july); earlier August coverage from 2026-08-06.