Executive Summary
Researcher Hyunwoo Kim (@v4bel) has disclosed a critical guest-to-host escape vulnerability dubbed 'Januscape' (CVE-2026-53359) affecting the Linux KVM hypervisor. The flaw, which remained dormant for 16 years, resides in the shadow MMU code shared by both Intel and AMD x86 architectures. It was successfully utilized as a zero-day submission in Google's kvmCTF program.
The vulnerability stems from a use-after-free condition where KVM improperly reuses shadow pages based on memory addresses alone, ignoring the page 'role.' This allows a malicious guest with root privileges to corrupt the host kernel's shadow-page state. In practice, this allows an attacker on a multi-tenant cloud environment to trigger a host-wide denial-of-service (panic) or achieve full remote code execution on the physical host, potentially compromising all other guest VMs.
While patches were released in early July 2026, the vulnerability poses a significant risk to cloud service providers and data centers utilizing nested virtualization. Immediate patching of the host kernel is required for any x86 environments running untrusted multi-tenant workloads.
Key Details
Threat Name
Januscape (CVE-2026-53359)
Affects
Linux KVM hypervisor, Intel x86 systems, AMD x86 systems, Linux kernel, KVM/arm64, KVM x86, KVM, KVM/x86, Linux kernel (2032a93d66fa to 81ccda30b4e8), GCP, AWS, RHEL, arm64-based KVM hosts
Adversary
—
Malware/Tools
Januscape, ITScape, Dirty Frag
