Ubuntu disclosed mitigation guidance for CVE-2026-53359 ("Januscape"), a Linux kernel local privilege escalation flaw affecting nested virtualization in KVM on Intel and AMD x86_64 systems. The issue impacts Ubuntu releases from 14.04 through 26.04, and a public proof-of-concept shows that a guest can crash the hypervisor host; Ubuntu warned that, in cloud environments with nested virtualization enabled, exploitation could potentially compromise the host or other tenants. The advisory said the required fix must be applied to the hypervisor kernel, while unprivileged containers are not affected; however, privileged containers and systems exposing /dev/kvm to non-privileged users may face elevated risk.
Canonical's Ubuntu CVE tracker lists CVE-2026-53359 among several high-priority Linux kernel vulnerabilities marked as affecting Ubuntu package families including linux, linux-hwe, linux-hwe-5.4, linux-hwe-5.8, and linux-hwe-5.11, with fixes noted as resolved upstream in the Linux kernel. Separate Linux security update notices also highlighted active kernel patching activity for other serious flaws, including CVE-2026-46331, a pedit subsystem privilege-escalation bug with a disclosed proof-of-concept reported to exist in the wild, and CVE-2026-52951, a drm/xe/dma-buf use-after-free issue that can trigger denial of service; organizations were urged to test and deploy distributor patches from vendors such as Ubuntu and Red Hat.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Ubuntu published guidance for CVE-2026-53359 on July 11, 2026, stating fixes were still pending and recommending disabling nested virtualization as a temporary mitigation. The notice warned that privileged containers and systems exposing /dev/kvm to non-privileged users may be at risk, while unprivileged containers were not a concern.
Ubuntu said the local privilege escalation flaw CVE-2026-53359, dubbed Januscape, was publicly disclosed on July 6, 2026. The bug affects nested virtualization in KVM on Intel and AMD x86_64 systems, and a proof-of-concept showed a guest could crash a hypervisor host.
Linux released security updates on June 28, 2026 to address multiple kernel vulnerabilities that could lead to denial of service, privilege escalation, information disclosure, data manipulation, security bypass, or arbitrary code execution. The notice specifically highlighted CVE-2026-46331 and CVE-2026-52951 and advised organizations to obtain distributor updates from vendors such as Red Hat and Ubuntu.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
ubuntu.com
Open sourceegfincirt-wpn.azurewebsites.net
Open sourceegfincirt.org.eg
Open sourceubuntu.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.