Zapscape 취약점으로 L1 게스트 코드가 리눅스 호스트로 탈출할 수 있다.
Zapscape는 새로운 리눅스 커널 취약점으로, L1 게스트 가상 머신에서 커널 권한을 가진 공격자가 KVM 격리를 우회하고 호스트에서 코드를 실행할 수 있게 한다. 이 취약점은 중첩 가상화가 신뢰할 수 없는 게스트에 노출될 때 위험이 발생한다. CVE-2026-64561로 추적되며, KVM/x86의 그림자 메모리 관리 장치에 영향을 미친다.
Zapscape vulnerability allows L1 guest code to escape to Linux hosts.
Zapscape is a new Linux kernel vulnerability that could allow an attacker with kernel privileges in an L1 guest virtual machine to escape KVM isolation and execute code on the host. This risk arises when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and impacts the shadow memory management unit of KVM/x86.