Junglewise Threat Intelligence

CVE-2026-64561: Linux KVM x86 shadow MMU privilege escalation

CVE-2026-64561 · Severity: high · CVSS 8.8 · Published 2026-08-07

Technologies: Google Cloud Platform, Linux Kernel. Vendors: Google, Linux.

Executive brief

The Linux kernel's virtualization module (KVM) on Intel and AMD processors contains a flaw in memory management that could allow a malicious virtual machine to escape its sandbox and access the underlying host system. This vulnerability could lead to complete compromise of all VMs running on an affected host and theft of data across customer environments. Google has automatically patched its managed Compute Engine infrastructure; however, customers running self-managed virtual machines must update their host kernel as soon as patches are available.

Technical details

This is a privilege escalation vulnerability in the KVM x86 shadow Memory Management Unit (MMU) implementation that affects both Intel and AMD platforms. The vulnerability could allow a guest VM to escape its isolation boundary and execute code with hypervisor-level privileges on the host. The attack is local to the hypervisor and requires no network access or authentication. While no active exploitation has been observed in the wild, this is a high-severity proactive patching effort. Patches are available through upstream Linux kernel distributions; Google Compute Engine managed instances have been automatically mitigated via live patching without customer downtime.

Affected products

  • Linux Linux kernel x86 KVM module (version range not specified)

Timeline

  • 2026-08-07: disclosed
  • 2026-08-07: advisory: GCP security bulletin GCP-2026-052 published

References

Related threats