Google pays $250K for Linux vulnerability allowing guest VM escapes
ResearchKVMOur summary
A critical vulnerability in the KVM virtualization component of Linux, identified as CVE-2026-53359, enables untrusted guest virtual machines to achieve root-level access on the host system. This flaw, dubbed Januscape, resides within the shadow MMU emulation and could allow attackers to disrupt or take control of cloud environments. Discovered after remaining undetected for 16 years, it impacts both AMD and Intel-based systems using KVM. Researchers have demonstrated a proof-of-concept exploit that crashes the host OS from within a guest VM.
Ars Technica (Security) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.