CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 485

As cited

Copy frozen at (site build).

vulnerabilities

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

A use-after-free vulnerability in Linux's KVM hypervisor, tracked as CVE-2026-53359, allows a guest virtual machine to corrupt the host kernel's shadow-page state on Intel and AMD x86 systems. The flaw, present for 16 years in the shadow MMU code, can be exploited to trigger host kernel panics, and a researcher indicates a more severe unexploited variant may exist.

Why it matters: Organizations running KVM virtualization on Intel or AMD systems face immediate risk of host compromise and denial of service from malicious or compromised guest VMs; patching this hypervisor vulnerability is critical for multi-tenant environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

A use-after-free vulnerability in Linux's KVM hypervisor, tracked as CVE-2026-53359, allows a guest virtual machine to corrupt the host kernel's shadow-page state on Intel and AMD x86 systems. The flaw, present for 16 years in the shadow MMU code, can be exploited to trigger host kernel panics, and a researcher indicates a more severe unexploited variant may exist.

Why it matters: Organizations running KVM virtualization on Intel or AMD systems face immediate risk of host compromise and denial of service from malicious or compromised guest VMs; patching this hypervisor vulnerability is critical for multi-tenant environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary