ARM64 KVM 가상화 코드에서 새로운 취약점이 발견되었습니다.
리눅스 커널의 KVM 가상화 코드에서 ARM64 프로세서를 위한 새로운 취약점이 발견되었습니다. 이 결함은 중첩 가상화가 활성화된 호스트에서 해제된 호스트 메모리 조각이 게스트 가상 머신에 노출될 수 있게 합니다. CVE-2026-89775로 추적되는 이 버그는 게스트가 호스트 커널 메모리에 읽기 및 쓰기를 할 수 있게 해주며, 연구자는 이를 이용해 게스트에서 탈출하여 호스트 머신에서 코드를 실행할 수 있다고 밝혔습니다.
A new flaw in Linux KVM for ARM64 allows guest access to host memory.
A new vulnerability has been discovered in the Linux kernel's KVM virtualization code for ARM64 processors. This flaw can leave a freed segment of host memory exposed to a guest virtual machine when nested virtualization is enabled. Tracked as CVE-2026-89775, the bug allows a guest to read and write to host kernel memory, enabling potential escape from the guest to run code on the host machine.