All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
ITScape: Guest-to-Host Escape in KVM/arm64
ITScape (CVE-2026-46316) is a KVM escape vulnerability in KVM/arm64 that allows a guest to escape to the host and execute commands on the host with kernel privileges (root). As far as is publicly known, this is the first guest-to-host escape exploit research targeting KVM/arm64. This is not one of the commonly disclosed QEMU escapes.
This vulnerability can threaten the guest-host isolation of KVM/arm64 hosts that run guests, particularly multi-tenant arm64 public clouds.
CVE-2026-46316 was reported to [email protected] and has been patched in mainline:
"ITScape" essentially refers only to CVE-2026-46316, for which a working exploit has been demonstrated. It is recommended to apply the following two patches:


Comments
Fuck
Will this affect my smart toaster?
damn parasite
alright, another works for provider/dev to patch.
At this point the concept of having a QEMU/KVM VM in itself is starting to feel risky
Fixed it for you
Yes
Even if you’re a big company doing private cloud that doesn’t help much because it’s not like you trust every application running on every VM
fucking RIP.
PoC is public already
https://github.com/V4bel/ITScape
Whos the first one to test this on their ARM Hetzner VM?
The vulnerability is in arch/arm64/kvm/vgic/. If you are not on an arm64 KVM host, you do not need to worry about this vulnerability.
I suppose all concepts tend towards their dissolution.
Yes it's targeted to arm64, most of the cloud servers are in arm64
while normal Proxmox VE runs on Intel 64 / AMD64 hardware isn't affected
Well, last time we had like 5 PE's on the Kernels.
This is just the first, WHO IS READY?
weeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
Hah, I didn't post it (this time)