Researchers have disclosed CVE-2026-89775, a critical flaw in the Linux kernel’s ARM64 KVM virtualization code. When nested virtualization is enabled, a guest can read and write freed host memory, creating a potential guest-to-host escape. Administrators should patch to Linux 6.18.51, 7.2.5, or 7.3-rc1, or verify that the experimental nested-virtualization feature is disabled.
Source