Januscape Flaw in Linux KVM’s MMU Code Enables VM Escape on Intel and AMD
ID: c70ee48e-f337-5be8-8912-33dddcf2e123
STIX ID: report--c70ee48e-f337-5be8-8912-33dddcf2e123
Feed Name: The Cyber Express
CVE-2026-53359 (Januscape) is a use-after-free vulnerability in KVM’s shadow MMU code that enables a guest VM to corrupt host shadow page state and escape to the host, potentially causing host kernel panic, DoS of co-tenants, or full host RCE; the flaw affects Intel and AMD KVM hosts, was present for ~16 years, a PoC can trigger panics, and the patch was merged on June 19, 2026 (commit 81ccda30b4e8) — administrators of multi-tenant x86 KVM hosts with nested virtualization should ensure the patch is applied.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
