Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems
ResearchLinux KernelKVM hypervisorOur summary
A newly reported Linux kernel issue, tracked as CVE-2026-53359 and dubbed Januscape, can be exploited by a guest VM to corrupt host state and gain execution on the underlying system via the KVM shadow MMU. This matters for multi-tenant x86 cloud environments—especially those with nested virtualization—because successful exploitation can lead to full host compromise, denial of service, or root-level code execution. Researchers note the flaw was present for 16 years and has been patched in the mainline kernel as of June 19.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.