CVE Tools

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems

SecurityWeekBy Ionut Arghire

ResearchLinux KernelKVM hypervisor

Our summary

A newly reported Linux kernel issue, tracked as CVE-2026-53359 and dubbed Januscape, can be exploited by a guest VM to corrupt host state and gain execution on the underlying system via the KVM shadow MMU. This matters for multi-tenant x86 cloud environments—especially those with nested virtualization—because successful exploitation can lead to full host compromise, denial of service, or root-level code execution. Researchers note the flaw was present for 16 years and has been patched in the mainline kernel as of June 19.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store