A critical security flaw has been discovered in the KVM (Kernel-based Virtual Machine) component of the Linux kernel, identified as CVE-2026-89775. This vulnerability allows a guest virtual machine (VM) running on an ARM64 architecture system to escape into the host operating system. The flaw has a CVSS score of 9.3, which indicates a high level of severity. The issue arises from a flaw in how the kernel calculates memory sizes, which can lead to improper memory access controls. Specifically, when a size calculation results in zero, the kernel mistakenly treats it as a valid size, allowing unauthorized memory access without triggering standard safeguards. The vulnerability can be exploited in two main ways. The first method allows a guest VM to break out of its virtual environment and access the host system. This is particularly concerning in environments where ARM64 resources are shared among multiple users or clients. The second method is even more dangerous, as it enables a regular user without administrative privileges to gain full root access on certain Linux distributions, such as Red Hat Enterprise Linux (RHEL). This is possible because the file /dev/kvm, which is essential for virtualization, is open for writing by all users on these systems. The vulnerability affects systems where nested virtualization is enabled on ARM64 architecture. Nested virtualization allows one virtual machine to run another, and it is not enabled by default in KVM. Users must activate it manually during system startup using the parameter kvm-arm.mode=nested. Additionally, the hardware must support this feature, which typically requires more recent processors. Users can check their kernel version using the command uname -r in the terminal. The vulnerability is not present in kernel versions earlier than 6.16 and has been patched in versions starting from 6.18.51 and 7.2.5. However, Red Hat has stated that no simple workaround exists, and applying the patch is necessary to fully resolve the issue. Hyunwoo Kim, the researcher who discovered the flaw, has shared details of the vulnerability but has not released exploit code. While the vulnerability is serious, there is currently no evidence that it is being actively exploited in the wild. Nevertheless, security experts recommend that users apply the relevant patches as soon as possible to protect their systems from potential threats.