Januscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape Attacks
ID: 562d7a9d-8cb6-5f2c-ba6e-8f5e1f5ce410
STIX ID: report--562d7a9d-8cb6-5f2c-ba6e-8f5e1f5ce410
Feed Name: Security Affairs
Januscape (CVE-2026-53359) is a 16-year-old use-after-free in the Linux KVM shadow MMU allowing a guest with root access and nested virtualization enabled to corrupt host kernel memory, crash hosts, and potentially achieve host code execution; a public PoC panics hosts and a full exploit was used in Google kvmCTF. The issue affects x86 (Intel and AMD), was fixed with a one-line change merged in June 2026 and backported to stable kernels on July 4, 2026; mitigation includes applying the kernel fix or disabling nested virtualization.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
