A newly disclosed vulnerability in the Linux kernel's KVM virtualization code for ARM64 processors could give a guest virtual machine read-write access to host kernel memory. The issue, tracked as CVE-2026-89775, was reported by The Hacker News.
The flaw can leave a freed piece of host memory exposed to a guest VM, and it is exploitable on hosts with nested virtualization enabled. In that configuration, a guest can read and write host kernel memory, according to the report.
The bug is specific to ARM64 KVM and highlights the risk that nested virtualization can introduce even when the underlying hypervisor code is otherwise carefully isolated.