logo

16-Year-Old Januscape KVM Escape Vulnerability Lets Attackers Compromise Linux Hosts

ID: 691fe379-ce27-5caf-bd35-57b08c92c6d4

STIX ID: report--691fe379-ce27-5caf-bd35-57b08c92c6d4

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-07-07

Date Updated: 2026-07-21

Author: Divya

...
...

A 16-year-old use-after-free flaw in KVM's shadow MMU (CVE-2026-53359, "Januscape") enables nested guest VMs to corrupt host kernel memory and escape to the host on both Intel and AMD platforms; a public PoC causes host kernel panics and the bug was active from 2010 until patched in June 2026, with documented zero-day exploitation in Google’s kvmCTF—administrators are urged to apply fixes and restrict nested virtualization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.