• Request consultation
  • Newsletter
  • Deutsch Deutsch German de
  • English English English en
  • Italiano Italiano Italian it
  • Nederlands Nederlands Dutch nl
Greenbone
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for Your Sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap & Lifecycle
  • Service & Support
    • Technical Support
    • Self-Learning Courses
    • Documents
  • Events
    • Cybersec Europe 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Careers
    • Contact
  • Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for your sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap and Lifecycle
    • Request IT Security
  • Service & Support
    • Technical Support
    • Self-Learning Courses
    • Documents
  • Events
    • Cybersec Europe 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Careers
    • Contact
    • Newsletter
  • Our Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • German
  • English
  • Italian
  • Dutch
Joseph Lee

CVE-2026-53359 (aka Januscape): VM Escape Hits Linux KVM/x86

Blog

Januscape, tracked as CVE-2026-53359 (CVSS 8.8), is a use-after-free vulnerability [CWE-825] in the Linux kernel KVM/x86 that can let a guest crash its host and potentially break guest-host isolation. The highest-risk targets are Intel and AMD x86_64 KVM hosts that expose nested virtualization, especially in environments that accept untrusted guests or allow users to create virtual machines. Large global data center operators worldwide now face the complex task of patching vast fleets of KVM hosts while minimizing disruption to customer workloads.

Active exploitation of CVE-2026-53359 has not yet been reported. The vulnerabilities original reporter, Hyunwoo Kim, claims that the bug was used as a zero-day in Google’s kvmCTF and has released a PoC capable of causing Denial of Service (DoS) of all VMs running on the host from within a single guest VM. Detailed technical analysis have also been published [1][2]. Numerous national CERT agencies have issued alerts indicating high global risk [3][4][5][6][7][8][9][10][11][12][13][14][15][16].

Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-53359 on Red Hat Enterprise Linux (RHEL), SUSE and openSUSE, AlmaLinux, Oracle Linux, Rocky Linux, Fedora, and Debian. Greenbone will continue to add vulnerability detection as more Linux distributions issue security advisories. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Illustration representing CVE-2026-53359 (Januscape), a VM escape vulnerability in Linux KVM/x86 virtualization

A Global Risk Assessment of CVE-2026-53359 (Januscape)

According to the original public disclosure, the flaw has existed for roughly 16 years. Furthermore, all x86 Linux distributions and kernels prior to the fix commit are affected. This means the scope of affected IT infrastructure is very broad, presenting significant global risk. Successful exploitation can result in guest-to-host escape, corruption of the host kernel’s shadow page, DoS, and potentially, compromise of other guest VMs on the same host. For global data center operators, that scope translates into the same challenge repeated across every site: rolling out patches to thousands of KVM hosts without knocking customer workloads offline.

According to a post on Ubuntu’s blog, the primary public PoC effectively demonstrates that a guest VM can crash its hypervisor host. Furthermore, the original report says CVE-2026-53359 was used as a zero-day exploit in the Google kvmCTF.

The Technical Assessment of CVE-2026-53359 (Januscape)

CVE-2026-53359 (CVSS 8.8) affects KVM nested virtualization on Intel and AMD x86_64 systems, while other architectures are not affected. If a cloud provider does not allow nested virtualization, instances are not affected through this path. However, nested virtualization is enabled by default in the Linux kernel. Successful exploitation allows guest-to-host escape, corruption of the host kernel’s shadow page, DoS, and compromise of other VM guests running on the same host.

Ubuntu’s blog notes that system services such as libvirt, lxd, multipass, and incus may allow potential attackers to create virtual machines, which can affect exposure. A separate risk path exists where /dev/kvm permissions are overly broad; if /dev/kvm is world-writable, an unprivileged user can achieve local privilege escalation to gain root-level privileges.

CVE-2026-53359 is a use-after-free in shadow MMU emulation caused by shadow-page reuse when the page role does not match the new use. The affected component is the Linux kernel KVM/x86 shadow paging path in arch/x86/kvm/mmu/mmu.c. The root cause is that the kvm_mmu_get_child_sp() function does not compare roles effectively. The mismatch can leave a stale rmap entry, leading to an exploitable pointer de-reference [CWE-825].

Products Affected by CVE-2026-53359 (Januscape)

All x86 Linux distributions after roughly 2014 and prior to the Linux kernel fix commit are affected, regardless of distribution. Because CVE-2026-53359 is a guest-to-host escape vulnerability, exploitation depends on the the target system being used as a KVM-based hypervisor and having nested virtualization enabled on a guest VM.

For Ubuntu environments, defenders should review Canonical’s Januscape mitigation guidance, which says all Ubuntu releases from Trusty (14.04) through Resolute (26.04) are are affected. While patches for Ubuntu are still pending, instructions for disabling nested virtualization are provided. For Red Hat environments, teams should compare deployed kernels against the fixed builds listed in Red Hat’s security data entry.

Mitigation for CVE-2026-53359 (aka Januscape)

Complete mitigation depends on installing the security updates for the specific Linux distribution. Prioritized mitigation should begin with identifying where nested virtualization is exposed on Linux KVM/x86 hypervisors, especially in multi-tenant environments or deployments that allow untrusted users to create or control guest VMs. Because exploitation may depend on guest control or access to virtualization interfaces, defenders should also review who can create VMs and whether device-node permissions around /dev/kvm expose an additional local privilege escalation path.

Summary

CVE-2026-53359 (aka Januscape; CVSS 8.8) is a high-impact virtualization-boundary vulnerability caused by a use-after-free flaw on Intel and AMD x86_64 Linux KVM deployments with nested virtualization enabled in the Linux kernel. The consequences include guest-to-host escape, and possible compromise of other guest VMs on the same host. At least one public proof-of-concept is available along with detailed technical analysis [1][2]. Active exploitation is not yet confirmed, but the volume of national CERT advisories flagging the flaw as a high global risk tells its own story [3][4][5][6][7][8][9][10][11][12][13][14][15][16].

Detection is already available: Greenbone’s OPENVAS ENTERPRISE FEED covers CVE-2026-53359 across Red Hat Enterprise Linux (RHEL), SUSE and openSUSE, AlmaLinux, Oracle Linux, Rocky Linux, Fedora, and Debian, with more distributions being added as their advisories land. A free two-week trial of OPENVAS SCAN with the OPENVAS ENTERPRISE FEED is the fastest way to see exactly where this vulnerability sits in your organization’s infrastructure.

Contact Test Now Buy Here Back to Overview
Joseph Lee
Joseph Lee

Joseph has had a varied and passionate background in IT and cyber security since the late 1980s. His early technical experience included working on an IBM PS/2, assembling PCs and programming in C++.

He also pursued academic studies in computer and systems engineering, anthropology and an MBA in technology forecasting.

Joseph has worked in data analytics, software development and, in particular, enterprise IT security. He specialises in vulnerability management, encryption and penetration testing.

LinkedIn

23. July 2026/by Joseph Lee
Share this entry
  • Share on LinkedIn
  • Share by Mail
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-23 16:59:132026-07-23 16:59:13CVE-2026-53359 (aka Januscape): VM Escape Hits Linux KVM/x86

Search

Search Search

Archive

  • 2026
  • 2025

Newsletter

Subscribe Now

OPENVAS BASIC

Our entry-level enterprise product

Test 14 Days Free of Charge

Products & Solutions

  • OPENVAS PRODUCTS
  • OPENVAS SECURITY INTELLIGENCE
  • OPENVAS SCAN
  • OPENVAS BASIC
  • OPENVAS FREE
  • OPENVAS AI
ISO9001-EN

Service & Support

  • Technical Support
  • FAQ
  • Documents
  • Warranty
  • Open Source Vulnerability Management
  • Cyber Resilience Act
ISO27001-EN

About us

  • About Greenbone
  • Partners
  • MSSP
  • License information
  • Privacy Statement
  • Terms & Conditions
ISO14001-EN

Contact with us

  • Contact
  • Newsletter
  • Media Contact
  • Careers
  • Security Response
  • Imprint
  • Grounding Page

Community

  • Community Portal
  • Community Forum
© Copyright - Greenbone AG 2020-2026
  • Link to LinkedIn
Link to: wp2shell: Exploit Chaining for Unauthenticated RCE in WordPress Link to: wp2shell: Exploit Chaining for Unauthenticated RCE in WordPress wp2shell: Exploit Chaining for Unauthenticated RCE in WordPress
Scroll to top Scroll to top Scroll to top
Contact
Request IT Security Contact Us Subscribe to Newsletter Follow on LinkedIn