Cowork

Claude doesn't have permission to use virtualization (/dev/kvm)

Last checked

The error

Virtualization isn't fully set up
Cowork runs in a secure local virtual machine. Claude doesn't have permission to use virtualization (/dev/kvm). Add your user to the 'kvm' group, then log out and back in.

Shown in the Cowork tab of Claude Desktop on Linux (beta, Ubuntu and Debian). Anthropic's docs list the line as: Claude doesn't have permission to use virtualization (/dev/kvm). This message is Linux only; macOS and Windows use different wording.

This is a Linux message. Cowork on Linux runs tasks in a QEMU/KVM virtual machine, and your user account cannot open /dev/kvm or /dev/vhost-vsock, which belong to the kvm group. Run sudo usermod -aG kvm $USER, then log out of your desktop session completely and log back in (or reboot). Claude Desktop checks this once at launch, so restart the app afterwards.

Why it happens

On Linux, /dev/kvm and /dev/vhost-vsock are owned by root with group kvm. Claude Desktop starts the Cowork VM as your user, so without kvm group membership it cannot use either device.

  1. Your user is not in the kvm group. This is the default on a fresh Ubuntu or Debian install where you have never used QEMU, libvirt or another VM tool.
  2. You joined the group but did not log out. Group membership is read at login, so a running Claude Desktop (and your current session) still has the old groups.
  3. /dev/kvm works through your desktop session's access rules but /dev/vhost-vsock does not. Anthropic's docs note that only kvm group members can open /dev/vhost-vsock, so join the group even if /dev/kvm already works (issue #80884).
  4. Your account comes from a directory service (for example authd with Entra ID), where usermod may not edit the group. A reporter fixed this with gpasswd instead (issue #80884).

The fix

  1. 1 Check the devices exist: ls -l /dev/kvm /dev/vhost-vsock. Both should show group kvm.
  2. 2 Add yourself to the group: sudo usermod -aG kvm $USER (for directory accounts, sudo gpasswd -a "$USER" kvm).
  3. 3 Log out of the desktop session completely and log back in, or reboot. Running newgrp kvm in a terminal does not change the groups of the Claude Desktop process.
  4. 4 Confirm it applied: run groups and check that kvm is listed.
  5. 5 Quit Claude Desktop fully and launch it again, then open the Cowork tab.
sudo usermod -aG kvm $USER

Other Cowork messages on Linux

Claude Desktop for Linux is in beta and supports Ubuntu 22.04 or later and Debian 12 or later, on x86_64 or arm64. The Cowork tab names the missing requirement, and each has its own fix:

Cowork requires hardware virtualization (KVM): turn on VT-x or AMD-V/SVM in BIOS/UEFI. If /dev/kvm does not exist at all, no group change will help.

Cowork requires QEMU: install qemu-system-x86, ovmf and virtiofsd on x86_64 (qemu-system-arm, qemu-efi-aarch64 and virtiofsd on arm64). apt install claude-desktop pulls these in unless you used --no-install-recommends.

Cowork requires the vhost_vsock kernel module: load it, then restart the app. To load it on every boot, add it to modules-load.d:

sudo modprobe vhost_vsock
echo vhost_vsock | sudo tee /etc/modules-load.d/vhost_vsock.conf

Older builds showed a vaguer error for the same permission problem: Workspace unavailable. The isolated Linux environment failed to start (not supported on this device), with yukonSilver not supported in cowork_vm_node.log (issue #80884). The kvm group fix applies to that too.

Is this the same as the Windows or macOS errors?

No. This wording comes from the Linux build. On Windows, Cowork depends on Virtual Machine Platform and the Windows hypervisor, and permission problems show up as different errors. Adding a user to a Hyper-V group or changing macOS privacy settings will not affect this message.

Still failing?

  • If ls shows no /dev/vhost-vsock and /lib/modules has no folder for your running kernel, the kernel lacks the support Cowork needs; Anthropic says this is common on ChromeOS and container-based Linux and cannot be added manually.
  • If you run Linux inside a VM, the host must expose nested virtualization, or /dev/kvm will not exist in the guest.
  • On distributions other than Ubuntu or Debian (Fedora, Arch), the desktop app is not supported; use the Claude Code CLI instead.

Related errors

Full guideClaude Cowork: The Complete Guide for 2026 (Setup, Fixes, Limits, and When to Use Something Else)

Hit a different error?

Paste any agent error and get the cause and fix in seconds.

Open the decoder

Frequently asked questions

Is it safe to add my user to the kvm group?

It is the standard permission model QEMU and libvirt use. It lets your user start hardware-accelerated VMs; it does not grant root.

I added the group and the error is still there. Why?

Group changes apply only to new login sessions. Log out fully or reboot, check groups lists kvm, then relaunch Claude Desktop, which checks requirements only at startup.

Does this message appear on macOS or Windows?

No. It is part of Cowork on Linux. Windows and macOS have their own virtualization errors with different fixes.

Stop firefighting agent errors

Decoding errors one at a time is the manual version of what BetterClaw automates. Run your agents on a no-code AI agent platform with managed models, retries and config validation built in.

Free plan available · Pro $49/mo · BYOK · 7-day money-back guarantee