ITScape (CVE-2026-46316) is a critical guest-to-host escape vulnerability located in the vGIC-ITS emulation of KVM/arm64. By exploiting a race condition that triggers a double-put use-after-free, an attacker with guest kernel privileges can execute arbitrary code on the host kernel, completely compromising the hypervisor and threatening multi-tenant cloud infrastructure.
arm64
1 post
How to defend ARM64 cloud infrastructure from ITScape