A Virtual Machine Could Keep Writing to Host Memory After the Page Was Freed
A guest virtual machine could keep a writable mapping to a host page after the host had freed it. From inside the VM, the attacker could then read and write 64 bits at a time without causing a trap or VM exit.
CVE-2026-89775 affects KVM on arm64 hosts where nested virtualisation is enabled. The researcher who disclosed it says the issue can support a guest-to-host escape in a multi-tenant cloud or reliable local privilege escalation where an unprivileged user can access /dev/kvm.
An empty invalidation range left a real mapping behind
The root cause is a truncated stage-one page-table walk level. The resulting size calculation returns zero, which elsewhere means that the size is unknown. The VNCR pseudo-TLB invalidation path instead treats zero as a real size, creates an empty interval and skips invalidation.
The host can free the page while the guest’s stale writable mapping remains. What looks like a bookkeeping error therefore crosses the virtualisation boundary and gives the guest a primitive against host memory.
The vulnerable configuration is not every ARM server
The published report is specific to arm64 KVM with nested virtualisation enabled. Operators should not turn that into a claim that all KVM, all Linux or all ARM systems are exposed. They should also not assume that a host is safe because they did not intentionally sell nested virtual machines. Development clouds, CI systems and research platforms may enable the feature for limited groups.
- Inventory arm64 hypervisors and record whether nested virtualisation is enabled.
- Map the running kernel package to the relevant distribution advisory rather than relying only on the upstream version.
- Restrict access to
/dev/kvmand review why each local user or service needs it. - Prioritise multi-tenant hosts and systems that allow untrusted users to create virtual machines.
- Patch and reboot into the fixed kernel, then verify the running build.
- Review host logs and workload history if untrusted guests ran during the exposed period.
The mainline fix landed on 6 August and the disclosed affected commit range begins in May 2025. Distribution kernels may backport both vulnerable code and fixes, so the vendor’s package status remains authoritative.
There is no claim in the cited disclosure that CVE-2026-89775 is being exploited in the wild. A public technical description of a host-escape primitive still makes unnecessary nested virtualisation an expensive convenience.
Sources
- Researcher disclosure to the oss-security list, dated 17 September 2026 in the message header.
- Mainline Linux kernel fix.


