home.social

#januscape — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #januscape, aggregated by home.social.

fetched live
  1. CVE-2026-64561 Zapscape Update:
    - Fixes for all affected versions of RHEL and Rocky Linux are available.
    - Debian bookworm fixes now available.
    - Ubuntu: 22.04, 24.04, and 26.04 vulnerable; no patches available yet.

    sketchesfromahomelab.com/artic

    #cve #cve_2026_53359 #cve_2026_64561 #januscape #kvm #linux #security #virtualization #zapscape

  2. CVE-2026-64561 Zapscape - another Januscape KVM guest-to-host escape vulnerability. Kernel patches are available, but release info from distributions is still incoming. Will update as more info becomes available!

    sketchesfromahomelab.com/artic

    Thanks @histrio for the initial alert!

    #cve #cve_2026_53359 #cve_2026_64561 #januscape #kvm #linux #security #virtualization

  3. I am doing cloud security. A use after free can kill the MMU memory in KVM.

    All Hyperscaler relying on KVM are affected.

    GitHub - V4bel/Januscape · GitHub
    github.com/V4bel/Januscape

    #kvm #cloud #gcp #azure #aws #security #januscape

  4. MT @[email protected]
    💥 Introducing "Januscape" (CVE-2026-53359)

    A Guest-to-Host Escape in KVM/x86 exploiting a UAF in the shadow MMU. Triggerable on both Intel and AMD hosts. Threatens x86 public clouds (GCP, AWS) that expose nested virtualization.

    Details: januscape.io

    #infosec #januscape #kvm

    GitHub - V4bel/Januscape

  5. MT @[email protected]
    💥 Introducing "Januscape" (CVE-2026-53359)

    A Guest-to-Host Escape in KVM/x86 exploiting a UAF in the shadow MMU. Triggerable on both Intel and AMD hosts. Threatens x86 public clouds (GCP, AWS) that expose nested virtualization.

    "16 years" latent. Successfully used as a 0-day exploit in "Google kvmCTF".

    To the best of public knowledge, the first KVM exploit research triggerable on both Intel and AMD.

    Details: januscape.io

    #infosec #januscape #kvm

  6. It received a CVE number: CVE-2026-53359. And there seems to be no mitigation until the fix arrives. You could unload the kvm module, but can you?

    Also issued a blog post about it almalinux.org/blog/2026-07-06-

  7. woop woop. The bug is legit and w̶e̶ ̶a̶l̶l̶ ̶g̶o̶o̶n̶a̶ ̶d̶i̶e̶ expect a lot of hype around it. The blast is big: you need /dev/kvm accessible via guest (which is quite often)

    I believe all major vendors have already prepared their fixes, so I guess it’s reboot time again.