<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Guest-to-Host-Escape — PoC Archive</title><link>https://poc.intelseclab.com/tags/guest-to-host-escape/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/guest-to-host-escape/index.xml" rel="self" type="application/rss+xml"/><item><title>Zapscape — KVM/x86 Shadow-MMU Recursive-Zap Guest-to-Host Escape (CVE-2026-64561)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-09_cve-2026-64561-zapscape-kvm-shadow-mmu-guest-to-host/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-09_cve-2026-64561-zapscape-kvm-shadow-mmu-guest-to-host/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-64561. Status: Patched. Affects: Linux kernel, KVM/x86 shadow-MMU (nested EPT/NPT shadowing) — arch/x86/kvm/mmu/mmu.c and arch/x86/kvm/mmu/paging_tmpl.h. Tags: linux-kernel, kvm, x86, shadow-mmu, nested-virtualization, svm, npt, ept, guest-to-host-escape, vm-escape, use-after-free, CWE-416, cross-cache, kaslr-bypass, usermode-helper, virtualization.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>kvm</category><category>x86</category><category>shadow-mmu</category><category>nested-virtualization</category><category>svm</category><category>npt</category><category>ept</category><category>guest-to-host-escape</category><category>vm-escape</category><category>use-after-free</category><category>CWE-416</category><category>cross-cache</category><category>kaslr-bypass</category><category>usermode-helper</category><category>virtualization</category></item><item><title>ITScape — KVM/arm64 vGIC-ITS Guest-to-Host VM Escape (CVE-2026-46316)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-46316-itscape-kvm-arm64-vgic-its-escape/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-46316-itscape-kvm-arm64-vgic-its-escape/</guid><description>Critical severity (CVSS 9.3) — binary · CVE-2026-46316 (GHSA-qcxh-2cm7-9fcc). Status: Weaponized. Affects: Linux kernel, KVM/arm64 in-kernel vGIC-ITS (Interrupt Translation Service) emulation (arch/arm64/kvm/vgic/vgic-its.c). Tags: linux-kernel, kvm, arm64, vgic-its, guest-to-host-escape, vm-escape, double-free, use-after-free, kaslr-bypass, heap-grooming, virtualization.</description><category>binary</category><category>Critical</category><category>linux-kernel</category><category>kvm</category><category>arm64</category><category>vgic-its</category><category>guest-to-host-escape</category><category>vm-escape</category><category>double-free</category><category>use-after-free</category><category>kaslr-bypass</category><category>heap-grooming</category><category>virtualization</category></item><item><title>QEMUtiny - QEMU CXL Type-3 Memory Corruption Chain</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-16_qemutiny-memory-corruption/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-16_qemutiny-memory-corruption/</guid><description>Critical severity — binary. Status: Weaponized. Affects: QEMU CXL Type-3 device emulation (hw/cxl/cxl-mailbox-utils.c). Tags: QEMU, CXL, memory-corruption, OOB-read, OOB-write, guest-to-host-escape, local, root-in-guest.</description><category>binary</category><category>Critical</category><category>QEMU</category><category>CXL</category><category>memory-corruption</category><category>OOB-read</category><category>OOB-write</category><category>guest-to-host-escape</category><category>local</category><category>root-in-guest</category></item></channel></rss>