HomeSecurityJanuscape: 16-year-old bug in KVM hypervisor allows guest-to-host escape

Januscape: 16-year-old bug in KVM hypervisor allows guest-to-host escape

A 16-year-old use-after-free vulnerability in the Linux kernel has come to light, revealing that a simple virtual machine can escape to the host on Intel and AMD. The flaw, dubbed Januscape and listed as CVE-2026-53359, is located in the shadow MMU code of the KVM hypervisor, the mechanism shared by the two largest processor manufacturers.

According to The Hacker News , the KVM Januscape vulnerability is described as the first guest-to-host exploit to be enabled on both Intel and AMD systems, as far as the public security literature knows. The fact that it has remained invisible since 2010 highlights how difficult it is to detect memory errors deep within critical virtualization code running on millions of servers worldwide.

What is Januscape and how does it work?

To run a virtual machine, KVM maintains page tables that mirror the guest's memory and reuses existing "watch pages." The problem: the shadow MMU code only mapped them based on memory address, ignoring their type; two different types could share the same address but serve different purposes, so KVM reused the wrong page.

This confusion corrupts the internal KVM files. In the mildest case, the kernel notices the inconsistency and immediately terminates; this is what causes the public PoC, bringing down the host along with any other virtual machines hosted there. In the worst case, the freed page is allocated for other use before the kernel can cleanup, and the cleanup then writes a value to memory that no longer belongs to it; the attacker only controls where the write lands, not what is written, but even that can be exploited to execute code on the host. The same code is triggered identically on Intel and AMD; only the last step differs between manufacturers.

KVM Januscape hypervisor virtualization

See also: Bad Epoll: PoC exploit for critical Linux vulnerability

Who is affected and how serious is it?

The vulnerable code has been around since commit 2032a93d66fa in August 2010, in the 2.6.36 kernel era, meaning Januscape had been active for about 16 years before it was discovered. The attack requires root inside the virtual machine, common in rented cloud instances, and nested virtualization enabled on the host. Even on hosts with EPT or NPT hardware by default, nested virtualization forces KVM to re-pass through the older shadow MMU, where the bug is hidden. The exploit does not require cooperation from QEMU or any userspace VMM; it is purely a bug within the KVM kernel.

Any x86 environment hosting untrusted guests with nested virtualization is at risk; an attacker can bring down the host by renting a single instance, dragging down every other tenant VM on the same machine. The researcher reported that the hidden exploit executes code as root on the host, exposing other guests as well. On RHEL, where /dev/kvm is world-writable (0666), the same flaw can also be used as a local privilege escalation to root, although the guest-to-host path remains more critical.

The researcher and Google's kvmCTF

The discovery was made by security researcher Hyunwoo Kim (@v4bel), who submitted Januscape as a zero-day submission to Google's kvmCTF, the KVM bounty program that offers up to $250,000 for complete guest-to-host escapes. Google launched the program in 2024 because KVM underpins both Android and Google Cloud.

See also: kvmCTF: Google's new VRP program for finding zero-day KVM vulnerabilities

KVM Januscape is Kim's third public Linux kernel vulnerability disclosure in two months: Dirty Frag (CVE-2026-43284 / CVE-2026-43500) in May 2026, a chain of page-cache vulnerabilities with deterministic root, and ITScape (CVE-2026-46316) in June, the first publicly demonstrated guest-to-host escape in KVM/arm64. Januscape now adds the x86 side. A separate use-after-free vulnerability in KVM x86 shadow paging (CVE-2026-46113) was patched in May 2026 — two such bugs in the same code in two months. The activity is reminiscent of other cases SecNews, such as Bad Epoll, as well as DirtyClone – pedit COW.

Januscape KVM patch Linux kernel fix

See also: DirtyClone – pedit COW: New Linux vulnerabilities for privilege escalation

Fixes and mitigation (The recommendations)

The fix for Januscape is a one-line addition to the kvm_mmu_get_child_sp() function: the reuse condition now checks role.word in addition to gfn, so that a shadow page is reused only when both its frame number and role match. The patch was written by KVM maintainer Paolo Bonzini in commit 81ccda30b4e8, which was merged into the mainline branch on June 19, 2026. The fixed stable versions were released on July 4, 2026: 7.1.3, 6.18.38, 6.12.95, 6.6.144, 6.1.177, 5.15.211, and 5.10.260. NVD has not yet assigned a CVSS score, which should not delay the update.

The SecNews technical team recommends that those managing x86 KVM hosts with multi-tenant guests and nested virtualization verify that their kernel includes commit 81ccda30b4e8. Backports may carry the fix with a different version number, so check the package changelog instead of relying on the uname -r command. If immediate updating is not possible, disabling nested virtualization via kvm_intel.nested=0 or kvm_amd.nested=0 removes the attack path for untrusted guests. ARM64 hosts are not affected by Januscape; ITScape (CVE-2026-46316) remains a separate issue, exclusive to KVM/arm64.

Public PoC demonstrates reliable host panic with loadable kernel module and few seconds of “race.” Those operating exposed x86 KVM hosts should treat patching as a priority, as Januscape demonstrates that 16-year-old code can pose risks to all cloud infrastructures.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS