Januscape Critical Linux KVM Guest-to-Host Escape
Score: 8/10

Januscape Critical Linux KVM Guest-to-Host Escape

A 16-year-old use-after-free vulnerability in the Linux KVM shadow MMU (CVE-2026-53359) allows guest VMs to escape to the host on x86 Intel and AMD systems.

Executive Summary

Researcher Hyunwoo Kim (@v4bel) has disclosed a critical guest-to-host escape vulnerability dubbed 'Januscape' (CVE-2026-53359) affecting the Linux KVM hypervisor. The flaw, which remained dormant for 16 years, resides in the shadow MMU code shared by both Intel and AMD x86 architectures. It was successfully utilized as a zero-day submission in Google's kvmCTF program.

The vulnerability stems from a use-after-free condition where KVM improperly reuses shadow pages based on memory addresses alone, ignoring the page 'role.' This allows a malicious guest with root privileges to corrupt the host kernel's shadow-page state. In practice, this allows an attacker on a multi-tenant cloud environment to trigger a host-wide denial-of-service (panic) or achieve full remote code execution on the physical host, potentially compromising all other guest VMs.

While patches were released in early July 2026, the vulnerability poses a significant risk to cloud service providers and data centers utilizing nested virtualization. Immediate patching of the host kernel is required for any x86 environments running untrusted multi-tenant workloads.

Key Details

Threat Name

Januscape (CVE-2026-53359)

Affects

Linux KVM hypervisor, Intel x86 systems, AMD x86 systems, Linux kernel, KVM/arm64, KVM x86, KVM, KVM/x86, Linux kernel (2032a93d66fa to 81ccda30b4e8), GCP, AWS, RHEL, arm64-based KVM hosts

Adversary

—

MITRE Techniques

Malware/Tools

Januscape, ITScape, Dirty Frag

Report Score

8out of 10
Quality Score
Good
IOC Quality4
TTP Details8
Detection Guidance6
Enterprise Relevance9
Clarity & Structure9
Technical Depth9

Sources