16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
A 16-year-old use-after-free vulnerability in Linux's KVM hypervisor, dubbed ‘Januscape’ (CVE-2026-53359), allows guest virtual machines to corrupt the host kernel's shadow-page state. Researcher Hyunwoo Kim discovered the flaw, which can be triggered with root access inside a guest VM and nested virtualization enabled on the host. The vulnerability has been present since 2010 and can lead to full host code execution, potentially compromising other guests on the same machine. A separate, more advanced exploit exists that allows code execution as root on the host. The vulnerability has been addressed in recent kernel versions.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
