A proof-of-concept (PoC) exploit has been publicly released for a critical Linux kernel vulnerability, tracked as CVE-2026-46316, enabling guest-to-host escape in KVM/arm64 environments.
The flaw, dubbed “ITScape” by security researcher Hyunwoo Kim (V4bel), affects the Kernel-based Virtual Machine (KVM) subsystem and allows a malicious guest virtual machine to execute arbitrary commands on the host with full kernel (root) privileges.
The issue has drawn significant attention due to its impact on virtualization security, particularly in multi-tenant cloud environments running ARM64 infrastructure.
The vulnerability resides in the vGIC-ITS (Virtual Generic Interrupt Controller – Interrupt Translation Service) emulation logic within the in-kernel KVM implementation.
Specifically, it is caused by a race condition that leads to a “double-put” scenario, ultimately enabling host kernel code execution.
Unlike traditional VM escape vulnerabilities that often target QEMU user-space components, ITScape exists entirely within the Linux kernel, making it more severe as exploitation yields direct kernel-level access rather than user-space process compromise.
According to the technical documentation and PoC released on GitHub, the exploit chain can be triggered purely through guest-side actions, without requiring interaction with user-space emulation layers.
The PoC demonstrates how a crafted guest workload performing specific GIC/ITS memory-mapped I/O (MMIO) operations can trigger the race condition, escape the virtualized environment, and execute code on the host.
Successful exploitation is verified by the creation of a file named “/ITScape” on the host system, owned by root, confirming privilege escalation beyond the guest boundary.
The released PoC is designed for controlled testing environments and uses QEMU TCG to emulate an ARM64 system, allowing researchers to reproduce the vulnerability safely. It is built on top of Linux KVM self-tests.
To compile the PoC on a vulnerable kernel tree (for example, Linux v7.1‑rc6, immediately prior to the fix), the researcher provides the following build invocation:
bash./build.sh <linux>/tools/testing/selftests/kvm Once compiled, the PoC binary is bundled into an initramfs, and QEMU is started with the supplied helper script:
bash./qemu.sh <kernel-image> <initramfs> Inside the emulated environment, an attacker (or tester) runs the PoC directly:
bash./poc It requires a vulnerable kernel version, specifically between commits 8201d1028caa (April 2024) and 13031fb6b835 (June 5, 2026), before the patch release.
While the PoC is not fully weaponized for real-world cloud exploitation, the researcher notes that adapting it to production environments would be feasible for attackers familiar with specific kernel configurations, memory layouts, and timing adjustments.
This vulnerability is particularly concerning for public cloud providers and environments that allow untrusted guest workloads on ARM64 hosts.
Since the exploit compromises the fundamental isolation guarantees of virtualization, successful attacks could enable lateral movement, data exfiltration, or full infrastructure takeover.
The disclosure followed a coordinated embargo via the Linux-distros security mailing list, and patches have been released to address the issue.
Security teams are strongly advised to update affected Linux kernels immediately and audit virtualization environments for exposure.
Additional mitigations include restricting untrusted guest execution, applying strict isolation policies, and monitoring for anomalous KVM or interrupt controller behavior.
The release of a functional PoC significantly increases the risk of exploitation in the wild, making timely patching and detection critical.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…