2026-07-09HIGHJanuscape (CVE-2026-53359): 16-year-old KVM shadow-MMU UAF gives a guest root a host escape on both Intel and AMD
Linux KVM/x86 'Januscape' shadow-MMU use-after-free, guest-to-host VM escape on Intel and AMD (public PoC host-DoS; RCE withheld); fixed 6.1.177/6.6.144/6.12.95/6.18.38/7.1.3
cve · CVE-2026-53359
Coverage
1
first 2026-07-09 → last 2026-08-08
Latest activity
2026-08-08
Januscape (CVE-2026-53359): 16-year-old KVM shadow-MMU UAF gives a guest root a host escape on both Intel and…
Peak priority
high
1 high
Targets
technology
sectors: technology, public-sector, finance · regions: europe
Sources cited
5
4 hosts
Action items (4)
Do-now tasks recorded on the entries about CVE-2026-53359, newest first. Check the date before acting on an older one.
- Patch KVM host kernels so they carry upstream commit 81ccda30b4e8 (2026-06-16), confirm your distro's stable kernel includes the backport; this is a host-kernel fix with no guest-side workaround or config toggle.2026-07-09CVE-2026-53359 +1
- On multi-tenant KVM estates, treat any unexplained host kernel panic/reboot that co-occurs with a single tenant's VM activity as a possible exploitation signal and preserve the host for forensics.2026-07-09CVE-2026-53359 +1
- Patch KVM host kernels so they carry both fixes (Januscape commit 81ccda30b4e8 and Zapscape commit 2abd5287f083); there is no guest-side mitigation for either, so a patched guest on an unpatched host is still exposed.2026-07-09CVE-2026-53359 +1
- Turn nested virtualization off for every tenant and workload that does not explicitly need it; where it must stay on for Intel guests, restrict exposure of EPT page-walk lengths 4 and 5 to L1, which is Zapscape's stated precondition.2026-07-09CVE-2026-53359 +1
Defender insights
What each entry about CVE-2026-53359 tells a defender to do, newest first.
Latest update
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (2 across 1 tactic)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Privilege EscalationExploitation for Privilege Escalation · Escape to Host
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation×1
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape · ATT&CK page ↗
T1611Escape to Host×1
Adversaries may break out of a container or virtualized environment to gain access to the underlying host. This can allow an adversary access to other containerized or virtualized resources from the host level or to the host itself. In principle, containerized / virtualized resources should provide a clear separation of application functionality and be isolated from the host environment.
Evidence: 2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape · ATT&CK page ↗
Entries about Linux KVM/x86 'Januscape' shadow-MMU use-after-free, guest-to-host VM escape on Intel and AMD (public PoC host-DoS; RCE withheld); fixed 6.1.177/6.6.144/6.12.95/6.18.38/7.1.3 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Linux Kernel (KVM/x86)×1
- Linux KVM/x86 'Zapscape'; use-after-free in the recursive shadow-MMU zap path gives guest-root-to-host escape (CVSS 8.8); needs nested virtualization, and on Intel EPT page-walk lengths 4 and 5 exposed to L1; fixed upstream 2abd5287f083×1
Where this entity is cited
Source distribution
- github.com2 (40%)
- bleepingcomputer.com1 (20%)
- ccb.belgium.be1 (20%)
- git.kernel.org1 (20%)
External references
All cited sources (5)
- bleepingcomputer.comprimaryBleepingComputerhttps://www.bleepingcomputer.com/news/linux/new-januscape-linux-kernel-flaw-allows-vm-escape-on-intel-amd-devices/
- ccb.belgium.beCentre for Cybersecurity Belgium (CCB)https://ccb.belgium.be/advisories/warning-vm-escape-vulnerabilities-kvm-patch-immediately
- git.kernel.orgLinux kernel upstream fix commithttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=81ccda30b4e8
- github.comHyunwoo Kim (V4bel), researcher write-up + PoChttps://github.com/V4bel/Januscape
- github.comV4bel, researcher write-uphttps://github.com/V4bel/Zapscape/blob/main/assets/write-up.md