Zapscape: Guest-to-Host Escape in KVM/x86
Summary
Zapscape (CVE-2026-64561) details a KVM/x86 guest-to-host escape vulnerability. The write-up explains a use-after-free in the shadow MMU recursive zap path that can escalate to host kernel root privileges, with PoC steps and an embargo/disclosure timeline. It highlights risk to multi-tenant clouds and calls for patching hypervisors promptly.