• Sources: primary, discussion
  • Summary: The embargo has ended on a shadow MMU use-after-free in KVM/x86 and the exploit is published on oss-security. A guest with L1 kernel privilege can run code as root on the host. Affected commits span 2020-07-08 to 2026-07-21. The author states that on Intel the bug can be triggered only when both EPT page walk length 4 and 5 are exposed to L1, and calls that condition necessary for assessing the affected scope. The published proof of concept also targets AMD and is demonstrated under QEMU TCG rather than as a weaponised exploit against a cloud hypervisor.
  • Why it matters: The same bug works as a local privilege escalation on distributions that ship /dev/kvm at mode 0666, so exposure is not limited to virtualization hosts.

send feedback on this story