CVE Tools

Google pays $250K for Linux vulnerability allowing guest VM escapes

Ars Technica (Security)By Dan Goodin

ResearchKVM

Our summary

A critical vulnerability in the KVM virtualization component of Linux, identified as CVE-2026-53359, enables untrusted guest virtual machines to achieve root-level access on the host system. This flaw, dubbed Januscape, resides within the shadow MMU emulation and could allow attackers to disrupt or take control of cloud environments. Discovered after remaining undetected for 16 years, it impacts both AMD and Intel-based systems using KVM. Researchers have demonstrated a proof-of-concept exploit that crashes the host OS from within a guest VM.

Read at Ars Technica (Security)

Ars Technica (Security) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store