16-Year-Old Januscape KVM Escape Vulnerability Lets Attackers Compromise Linux Hosts
ID: 691fe379-ce27-5caf-bd35-57b08c92c6d4
STIX ID: report--691fe379-ce27-5caf-bd35-57b08c92c6d4
Feed Name: GBHackers
Threat Score
A 16-year-old use-after-free flaw in KVM's shadow MMU (CVE-2026-53359, "Januscape") enables nested guest VMs to corrupt host kernel memory and escape to the host on both Intel and AMD platforms; a public PoC causes host kernel panics and the bug was active from 2010 until patched in June 2026, with documented zero-day exploitation in Google’s kvmCTF—administrators are urged to apply fixes and restrict nested virtualization.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
