INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Januscape Linux KVM Flaw Enables Cloud VM Escape Attacks
| 2026-07-07 12:06 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The discovery of a 16-year-old Linux kernel vulnerability, dubbed Januscape, has significant implications for cloud-based virtual machine (VM) security. This flaw allows attackers to escape from VMs and execute arbitrary code on the host operating system, posing a distinct risk in multi-tenant public cloud environments such as those offered by Google Cloud and Amazon Web Services. The vulnerability stems from a use-after-free weakness in the shadow MMU emulation of KVM/x86, a kernel-based virtual machine built for x86 and x86_64 processor architectures. This means that even on patched systems, Januscape can still be exploited to gain root permissions or execute malicious code. As such, security teams must remain vigilant and implement measures to prevent cloud VM escape attacks, including monitoring logs for suspicious activity and patching vulnerable systems promptly.
Technical Mitigations AI-generated
* Ensure that the Linux kernel is up-to-date, specifically patching commit 81ccda30b4e8 on hosts running KVM/x86 to confirm they have been patched against CVE-2026-53359.
* Implement a guest-to-host escape prevention mechanism for cloud VMs by verifying that the host kernel has been updated with the latest patches before accepting multi-tenant guests.
* Configure Linux systems to use secure memory management practices, such as using address space layout randomization (ASLR) and data execution prevention (DEP), to reduce the likelihood of guest-to-host escape vulnerabilities.
* Regularly monitor system logs for suspicious activity related to cloud VMs or KVM-based virtual machines, and alert security teams when potential exploits are detected.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ro•••••.word
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-53359CVE-2026-53359
CVE-2026-43500CVE-2026-43500
CVE-2026-43284CVE-2026-43284
CVE-2026-46113CVE-2026-46113
CVE-2026-46316CVE-2026-46316
Target & Sectors
Global Scope
Incident Timeline
2010/08/01
Januscape (CVE-2026-53359) was exploited to target guest virtual machines on January 1, 2010.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-53359
“Januscape (CVE-2026-53359) covers the range from
2032a93d66fa (2010-08-01)
to
81ccda30b4e8 (2026-06-16)
.”
August 2010
The incident affected systems running kernel 2.6.36 era with CVE-2026-53359, which was present since August 2010 and fixed by June 19, 2026.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-53359
The bug, tracked as CVE-2026-53359 and named Januscape, has been sitting in the kernel since August 2010.
infrastructure
2.6.36
Who Is Affected
The vulnerable code has been present since
commit 2032a93d66fa
in August 2010 (kernel 2.6.36 era) and was fixed by
commit 81ccda30b4e8
, merged into mainline on June 19, 2026.
May 2026
Kim disclosed a page-cache write vulnerability exploit called Dirty Frag that enables guest VM escape attacks.
Click on any entity below to view its context and source!
tactic
Privilege Escalation
In May 2026, Kim also disclosed
Dirty Frag
, a Linux local privilege escalation flaw that chains xfrm-ESP (
CVE-2026-43284
) and RxRPC (
CVE-2026-43500
) page-cache write vulnerabilities to gain root access on major distributions, including Ubuntu, Red Hat Enterprise Linux, CentOS Stream, and Fedora.
vulnerability
CVE-2026-43284
In May 2026, Kim also disclosed
Dirty Frag
, a Linux local privilege escalation flaw that chains xfrm-ESP (
CVE-2026-43284
) and RxRPC (
CVE-2026-43500
) page-cache write vulnerabilities to gain root access on major distributions, including Ubuntu, Red Hat Enterprise Linux, CentOS Stream, and Fedora.
In May 2026, he disclosed
Dirty Frag
(CVE-2026-43284 and CVE-2026-43500), a page-cache write vulnerability chain that delivers reliable root on most major Linux distributions, extending the same vulnerability class as
Dirty Pipe
and
Copy Fail
.
In May 2026, he disclosed
Dirty Frag
(
CVE-2026-43284 / CVE-2026-43500
), a page-cache write vulnerability chain that delivers deterministic root on most major distributions, extending the same bug class as Dirty Pipe and Copy Fail.
vulnerability
CVE-2026-43500
In May 2026, Kim also disclosed
Dirty Frag
, a Linux local privilege escalation flaw that chains xfrm-ESP (
CVE-2026-43284
) and RxRPC (
CVE-2026-43500
) page-cache write vulnerabilities to gain root access on major distributions, including Ubuntu, Red Hat Enterprise Linux, CentOS Stream, and Fedora.
In May 2026, he disclosed
Dirty Frag
(CVE-2026-43284 and CVE-2026-43500), a page-cache write vulnerability chain that delivers reliable root on most major Linux distributions, extending the same vulnerability class as
Dirty Pipe
and
Copy Fail
.
In May 2026, he disclosed
Dirty Frag
(
CVE-2026-43284 / CVE-2026-43500
), a page-cache write vulnerability chain that delivers deterministic root on most major distributions, extending the same bug class as Dirty Pipe and Copy Fail.
infrastructure
Linux
In May 2026, Kim also disclosed
Dirty Frag
, a Linux local privilege escalation flaw that chains xfrm-ESP (
CVE-2026-43284
) and RxRPC (
CVE-2026-43500
) page-cache write vulnerabilities to gain root access on major distributions, including Ubuntu, Red Hat Enterprise Linux, CentOS Stream, and Fedora.
In May 2026, he disclosed
Dirty Frag
(CVE-2026-43284 and CVE-2026-43500), a page-cache write vulnerability chain that delivers reliable root on most major Linux distributions, extending the same vulnerability class as
Dirty Pipe
and
Copy Fail
.
organisation
Ubuntu, Red Hat Enterprise Linux
In May 2026, Kim also disclosed
Dirty Frag
, a Linux local privilege escalation flaw that chains xfrm-ESP (
CVE-2026-43284
) and RxRPC (
CVE-2026-43500
) page-cache write vulnerabilities to gain root access on major distributions, including Ubuntu, Red Hat Enterprise Linux, CentOS Stream, and Fedora.
organisation
CVE-2026
In May 2026, he disclosed
Dirty Frag
(CVE-2026-43284 and CVE-2026-43500), a page-cache write vulnerability chain that delivers reliable root on most major Linux distributions, extending the same vulnerability class as
Dirty Pipe
and
Copy Fail
.
general_metric
43500 Dirty Frag
In May 2026, he disclosed
Dirty Frag
(CVE-2026-43284 and CVE-2026-43500), a page-cache write vulnerability chain that delivers reliable root on most major Linux distributions, extending the same vulnerability class as
Dirty Pipe
and
Copy Fail
.
organisation
Dirty Pipe
In May 2026, he disclosed
Dirty Frag
(
CVE-2026-43284 / CVE-2026-43500
), a page-cache write vulnerability chain that delivers deterministic root on most major distributions, extending the same bug class as Dirty Pipe and Copy Fail.
organisation
Copy Fail
In May 2026, he disclosed
Dirty Frag
(
CVE-2026-43284 / CVE-2026-43500
), a page-cache write vulnerability chain that delivers deterministic root on most major distributions, extending the same bug class as Dirty Pipe and Copy Fail.
vulnerability
CVE-2026-46113
A separate KVM x86 shadow paging use-after-free (
CVE-2026-46113
) involving a related but distinct rmap mismatch was fixed in May 2026.
June 2026
Januscape exploit was used to enable guest VM escape attacks in Google's kvmCTF vulnerability reward program.
Click on any entity below to view its context and source!
infrastructure
Linux
Januscape has been present in the Linux kernel for approximately 16 years before being
patched in June 2026
, and was used as a zero-day exploit in Google's kvmCTF vulnerability reward program (VRP).
organisation
Januscape
Januscape has been present in the Linux kernel for approximately 16 years before being
patched in June 2026
, and was used as a zero-day exploit in Google's kvmCTF vulnerability reward program (VRP).
organisation
Google
Januscape has been present in the Linux kernel for approximately 16 years before being
patched in June 2026
, and was used as a zero-day exploit in Google's kvmCTF vulnerability reward program (VRP).
organisation
kvmCTF
Januscape has been present in the Linux kernel for approximately 16 years before being
patched in June 2026
, and was used as a zero-day exploit in Google's kvmCTF vulnerability reward program (VRP).
organisation
VRP
Januscape has been present in the Linux kernel for approximately 16 years before being
patched in June 2026
, and was used as a zero-day exploit in Google's kvmCTF vulnerability reward program (VRP).
2026/06/16
Januscape (CVE-2026-53359) was exploited to enable guest VM escape attacks on the target date of June 16, 2026.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-53359
“Januscape (CVE-2026-53359) covers the range from
2032a93d66fa (2010-08-01)
to
81ccda30b4e8 (2026-06-16)
.”
June 19, 2026
Threat actors exploited a vulnerability in the 2.6.36 kernel, which was fixed six years later on June 19, 2026.
Click on any entity below to view its context and source!
infrastructure
2.6.36
Who Is Affected
The vulnerable code has been present since
commit 2032a93d66fa
in August 2010 (kernel 2.6.36 era) and was fixed by
commit 81ccda30b4e8
, merged into mainline on June 19, 2026.
July 4, 2026
Guest VM escape attacks were enabled by exploiting a vulnerability in Januscape, which was fixed on July 4, 2026.
2026/07/07
Hyunwoo Kim used a use-after-free bug in Linux's KVM hypervisor to enable guest-to-host escape attacks on Intel and AMD systems.
Click on any entity below to view its context and source!
infrastructure
Linux
New Januscape Linux flaw allows VM escape on Intel, AMD devices.
A 16-year-old Linux kernel vulnerability, dubbed
Januscape
, allows attackers to escape a virtual machine and execute arbitrary code on the host.
"
On some Linux distros, such as Red Hat Enterprise Linux (RHEL), where /dev/kvm is world-writable, unprivileged attackers can also exploit CVE-2026-53359 to reliably gain root permissions on unpatched devices.
Kernel-based Virtual Machine (KVM) is a virtualization technology built directly into the Linux kernel that allows one physical computer to run multiple independent virtual machines (VMs).
Januscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape Attacks.
Januscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape Attacks
Januscape: A 16-year-old Linux KVM flaw lets cloud VM tenants crash hosts and potentially escape guests.
Security researcher
Hyunwoo Kim
has published details of a use-after-free vulnerability in Linux’s KVM hypervisor that allows code running inside a guest virtual machine to corrupt host kernel memory.
Once KVM’s internal records become incorrect, the Linux kernel may handle invalid data, causing crashes or potentially allowing an attacker to gain control.
Januscape is Kim’s third significant Linux kernel exploit in roughly two months.
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems.
A use-after-free bug in Linux's KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it.
A Busy Few Months for One Researcher
Januscape is Kim's third Linux kernel exploit disclosure in roughly two months.
organisation
Intel
New Januscape Linux flaw allows VM escape on Intel, AMD devices.
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems.
It affects Intel and AMD systems.
organisation
AMD
New Januscape Linux flaw allows VM escape on Intel, AMD devices.
It affects Intel and AMD systems.
Dubbed '
Januscape
' and tracked as
CVE-2026-53359
, the flaw sits in the shadow MMU code that KVM shares across both Intel and AMD.
organisation
Red Hat Enterprise Linux
"
On some Linux distros, such as Red Hat Enterprise Linux (RHEL), where /dev/kvm is world-writable, unprivileged attackers can also exploit CVE-2026-53359 to reliably gain root permissions on unpatched devices.
organisation
Kernel
Kernel-based Virtual Machine (KVM) is a virtualization technology built directly into the Linux kernel that allows one physical computer to run multiple independent virtual machines (VMs).
organisation
Virtual Machine
Kernel-based Virtual Machine (KVM) is a virtualization technology built directly into the Linux kernel that allows one physical computer to run multiple independent virtual machines (VMs).
organisation
AMD x86 Systems
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems.
organisation
KVM
Dubbed '
Januscape
' and tracked as
CVE-2026-53359
, the flaw sits in the shadow MMU code that KVM shares across both Intel and AMD.
KVM maintains its own internal set of page tables to track a guest’s memory layout.
organisation
MMU
According to Hyunwoo Kim, the security researcher
who discovered it
, this guest-to-host escape flaw (tracked as
CVE-2026-53359
) stems from a use-after-free weakness in the shadow MMU emulation of KVM/x86, the kernel-based virtual machine built for x86 and x86_64 (AMD64) processor architectures.
Even on hosts that run hardware EPT or NPT by default, nested virtualization forces KVM back through the legacy shadow MMU, which is where the bug sits.
organisation
x86_64
According to Hyunwoo Kim, the security researcher
who discovered it
, this guest-to-host escape flaw (tracked as
CVE-2026-53359
) stems from a use-after-free weakness in the shadow MMU emulation of KVM/x86, the kernel-based virtual machine built for x86 and x86_64 (AMD64) processor architectures.
organisation
NPT
Even on hosts that run hardware EPT or NPT by default, nested virtualization forces KVM back through the legacy shadow MMU, which is where the bug sits.
organisation
Google
According to Kim, the exploit was used as a zero-day submission in
Google's kvmCTF
, the controlled KVM vulnerability reward program that offers up to $250,000 for full guest-to-host escapes.
financial
$250,000 program
According to Kim, the exploit was used as a zero-day submission in
Google's kvmCTF
, the controlled KVM vulnerability reward program that offers up to $250,000 for full guest-to-host escapes.
Kim used it as a zero-day submission in Google’s kvmCTF program, which offers up to $250,000 for full guest-to-host escapes.
organisation
kvmCTF
Google launched kvmCTF in 2024 specifically because KVM underpins both Android and Google Cloud.
infrastructure
Android
Google launched kvmCTF in 2024 specifically because KVM underpins both Android and Google Cloud.
organisation
Google Cloud
Kim described Januscape as the first guest-to-host exploit that can be triggered on both Intel and AMD processor architectures, rather than being limited to a single platform, and
noted
that it poses a distinct risk to multi-tenant public cloud environments, such as those offered by Google Cloud and Amazon Web Services.
organisation
DoS
"For example, an attacker who has rented just a single instance on a public cloud could panic the host kernel to take down every other tenant VM on the same physical machine (DoS), or run code with root privilege on the host to take over the host and all the guests on it (RCE).
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
organisation
ITScape
ARM64 KVM hosts aren’t affected by Januscape specifically, though Kim’s earlier ITScape disclosure (CVE-2026-46316) covers a separate guest-to-host issue on that architecture.
ARM64 hosts are not affected by Januscape; ITScape (CVE-2026-46316) is a separate KVM/arm64 issue.
organisation
Google’s kvmCTF
Kim used it as a zero-day submission in Google’s kvmCTF program, which offers up to $250,000 for full guest-to-host escapes.
organisation
GCP
It can trigger the bug with guest-side actions alone to corrupt the host kernel’s shadow page, and it can threaten the guest-host isolation of KVM/x86 hosts that accept untrusted guests and expose nested virtualization, particularly multi-tenant x86 public clouds (GCP, AWS, etc.).”
states
Kim.
organisation
AWS
It can trigger the bug with guest-side actions alone to corrupt the host kernel’s shadow page, and it can threaten the guest-host isolation of KVM/x86 hosts that accept untrusted guests and expose nested virtualization, particularly multi-tenant x86 public clouds (GCP, AWS, etc.).”
states
Kim.
organisation
QEMU
“Unlike the commonly published QEMU escape vulnerabilities, Januscape occurs in in-kernel KVM, so it is triggered independently of QEMU’s emulation.
The exploit needs no cooperation from QEMU or any userspace VMM.
organisation
VMM
The exploit needs no cooperation from QEMU or any userspace VMM.
organisation
NVD
NVD hasn’t assigned a CVSS score yet.
NVD has not yet assigned a CVSS score; do not wait for one.
organisation
CVSS
NVD hasn’t assigned a CVSS score yet.
NVD has not yet assigned a CVSS score; do not wait for one.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Januscape)
organisation
PoC
Januscape now adds the x86 side; the same trigger fires on both Intel and AMD, with the PoC carrying a separate code path for each vendor.
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
In May 2026, Kim also disclosed
Dirty Frag
, a Linux local privilege escalation flaw that chains xfrm-ESP (
CVE-2026-43284
) and RxRPC (
CVE-2026-43500
) page-cache write vulnerabilities to gain root access on major distributions, including Ubuntu…
New Januscape Linux flaw allows VM escape on Intel, AMD devices.
A 16-year-old Linux kernel vulnerability, dubbed
Januscape
, allows attackers to escape a virtual machine and execute arbitrary code on the host.
Januscape has been present in the Linux kernel for approximately 16 years before being
patched in June 2026
, and was used as a zero-day exploit in Google's kvmCTF vulnerability reward program (VRP).
"
On some Linux distros, such as Red Hat Enterprise Linux (RHEL), where /dev/kvm is world-writable, unprivileged attackers can also exploit CVE-2026-53359 to reliably gain root permissions on unpatched devices.
Kernel-based Virtual Machine (KVM) is a virtualization technology built directly into the Linux kernel that allows one physical computer to run multiple independent virtual machines (VMs).
Januscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape Attacks.
Januscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape Attacks
Januscape: A 16-year-old Linux KVM flaw lets cloud VM tenants crash hosts and potentially escape guests.
Security researcher
Hyunwoo Kim
has published details of a use-after-free vulnerability in Linux’s KVM hypervisor that allows code running inside a guest virtual machine to corrupt host kernel memory.
Once KVM’s internal records become incorrect, the Linux kernel may handle invalid data, causing crashes or potentially allowing an attacker to gain control.
Januscape is Kim’s third significant Linux kernel exploit in roughly two months.
In May 2026, he disclosed
Dirty Frag
(CVE-2026-43284 and CVE-2026-43500), a page-cache write vulnerability chain that delivers reliable root on most major Linux distributions, extending the same vulnerability class as
Dirty Pipe
and
Copy Fail
.
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems.
A use-after-free bug in Linux's KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it.
A Busy Few Months for One Researcher
Januscape is Kim's third Linux kernel exploit disclosure in roughly two months.
Metrics
financial
250,000
Program
Kim used it as a zero-day submission in Google’s kvmCTF program, which offers up to $250,000 for full guest-to-host escapes.
According to Kim, the exploit was used as a zero-day submission in
Google's kvmCTF
, the controlled KVM vulnerability reward program that offers up to $250,000 for full guest-to-host escapes.
Metrics
infrastructure
2.6.36
Software Version
Who Is Affected
The vulnerable code has been present since
commit 2032a93d66fa
in August 2010 (kernel 2.6.36 era) and was fixed by
commit 81ccda30b4e8
, merged into mainline on June 19, 2026.
Metrics
infrastructure
Android
Affected Product
Google launched kvmCTF in 2024 specifically because KVM underpins both Android and Google Cloud.
Intelligence Sources
BleepingComputer
2026-07-07
New Januscape Linux flaw allows VM escape on Intel, AMD devices
BleepingComputer
Security Affairs
2026-07-07
Januscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape Attacks
Security Affairs
The Hacker News
2026-07-06
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-08T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
31x
organisation
Identified Entity
Ubuntu, Red Hat Enterprise Linux
entity
15x
timeline
Temporal Reference
May 2026
date
5x
vulnerability
Exploited CVE
CVE-2026-43284
cve
2x
tactic
Cyber Operation Type
Privilege Escalation
tactic
2x
infrastructure
Affected Product
Linux
software
2x
tactic
MITRE ATT&CK Technique
T1584.006 - Web Services
technique
2x
general metric
%
54
%
Contextual Telemetry
Context Block
4 METRICS
industry
Targeted Sector
Technology
sector
general metric
Dirty Frag
43,500
dirty frag
financial
Program
250,000
program
infrastructure
Software Version
2.6.36
version
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.