<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Virtualisation on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/virtualisation/</link><description>Recent content in Virtualisation on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Fri, 19 Jun 2026 08:43:42 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/virtualisation/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-48914: QEMU-KVM Heap Overflow in Azure</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-48914-qemu-kvm-heap-buffer-overflow-virtio-blk-azure/</link><pubDate>Fri, 19 Jun 2026 08:43:42 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-48914-qemu-kvm-heap-buffer-overflow-virtio-blk-azure/</guid><description>CVE-2026-48914 is a heap buffer overflow in QEMU-KVM&amp;#39;s virtio-blk SCSI handling, risking VM escape on Azure and self-managed KVM hosts.</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48914">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-48914 is a heap buffer overflow vulnerability in QEMU-KVM&rsquo;s virtio-blk driver, specifically in how it handles SCSI requests. This type of flaw can potentially allow a malicious guest virtual machine to corrupt host memory, which in a cloud environment could lead to VM escape — one of the most severe hypervisor-level threats. Microsoft has published this advisory via the MSRC, indicating Azure infrastructure may be affected.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Assess whether your Azure workloads rely on virtualisation layers exposed to untrusted guest workloads; prioritise patching any Azure host infrastructure or self-managed QEMU-KVM deployments. If you operate multi-tenant environments or nested virtualisation, treat this as urgent and monitor Microsoft&rsquo;s patch guidance closely.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48914">CVE-2026-48914 Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling</a></p>
]]></content:encoded></item><item><title>CVE-2026-42915 Windows VMSwitch DoS Vulnerability</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-42915-windows-vmswitch-denial-of-service-vulnerability/</link><pubDate>Tue, 16 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-42915-windows-vmswitch-denial-of-service-vulnerability/</guid><description>CVE-2026-42915 is a Denial of Service flaw in Windows VMSwitch affecting Hyper-V and Azure. Advisory updated with corrected title and description.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42915">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-42915 is a Denial of Service vulnerability affecting Microsoft Windows VMSwitch, a core component of Hyper-V networking used in Azure virtualisation infrastructure. The advisory has been updated to correct the CVE description and title, with no change to the underlying vulnerability details or patches. While classified as a DoS vulnerability, its presence in virtualisation switching layers means it could impact availability across hosted workloads.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Verify that any previously applied mitigations or patches for CVE-2026-42915 align with the corrected description — the title change may indicate a scope clarification. Ensure your vulnerability management tooling has ingested the updated advisory and re-assess risk ratings if your environment relies on Windows Hyper-V or Azure VMSwitch networking.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42915">CVE-2026-42915 Microsoft Windows VMSwitch Denial of Service Vulnerability</a></p>
]]></content:encoded></item></channel></rss>