Post #3720245
2026-07-07 17:45 UTC
Haven't seen a big splash in the (IT) news yet, but apparently there is a 16 year old vulnerability in KVM which can be used to escape a guest and even take over the host (CVE-2026-53359): https://github.com/V4bel/Januscape. If /dev/kvm is available (world-writable on the host), it can also be used as a LPE to root.
This is kind of bad. REALLY bad.
Replies (0)
No replies.