Januscape (CVE-2026-53359) is a use-after-free vulnerability in Linux kernel KVM x86 shadow paging. When an externally modified page-directory entry changes a large 2 MiB mapping to a non-leaf mapping for 4 KiB pages, kvm_mmu_get_child_sp() can reuse a shadow page whose guest frame number matches but whose role is incompatible. The reused page retains direct=1 rather than the required direct=0. During cleanup, kvm_mmu_page_get_gfn() consequently computes the wrong guest frame number, preventing removal of a reverse-mapping entry. Removing the memory slot frees the shadow page while leaving that entry intact. Subsequent dirty logging, MMU notifier invalidation, or other reverse-map traversal can dereference freed memory. The vulnerability remains after an earlier fix for a related guest-frame-number mismatch.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (10 hidden).
This repository is a small Linux-host-side hotpatch project, not a guest-to-host escape exploit. It contains a kernel module (KVM-XJ.c), a Makefile to build it against the running kernel, a README describing CVE-2026-53359 ('Januscape'), and a helper script (dump_tool.py) to identify the correct instruction offset in different kvm.ko builds. Core capability: the module dynamically resolves the kernel symbols kvm_mmu_get_page and text_poke using kallsyms_lookup_name, pauses CPUs with stop_machine, saves 6 original bytes from kvm_mmu_get_page+0x108, and overwrites them with a 6-byte NOP sequence. According to the README and code comments, this removes a conditional jump after a gfn comparison so the vulnerable shadow page reuse path is skipped and KVM falls back to allocating a new page. On module unload, the original bytes are restored. Repository structure: - KVM-XJ.c: main kernel module implementing the live patch. - Makefile: standard out-of-tree kernel module build instructions. - dump_tool.py: offline ELF parser/pattern matcher that scans a supplied kvm.ko for kvm_mmu_get_page and nearby compare/jump instruction patterns, then prints the likely patch offset. - README.md: explains the vulnerability, patch rationale, deployment steps, tested kernel versions, and operational caveats. There are no network callbacks, C2 endpoints, or remote targets in the code. The only meaningful observables are local kernel symbols and filesystem paths related to kernel module compilation and analysis. Because the code performs a real in-memory kernel text modification with a fixed payload and requires local root access, its maturity is best classified as OPERATIONAL. It is exploit-adjacent in that it targets a vulnerability, but its purpose is mitigation rather than exploitation.
This repository contains a real proof-of-concept exploit for CVE-2026-53359 ('Januscape'), a guest-to-host KVM/x86 escape vulnerability caused by a use-after-free in the shadow MMU path. The released exploit is not a full host-code-execution weapon; it is a kernel-module PoC intended to trigger a host denial of service by causing the host KVM kernel to panic. The repository is small and centered on one main code artifact: Januscape-V4bel/poc.c, supported by a Makefile and extensive Markdown documentation. Structure: the top-level README is mostly generic wrapper text plus a reference to the upstream Januscape material. The meaningful exploit content lives under Januscape-V4bel/: README.md explains the vulnerability, prerequisites, and usage; assets/write-up.md provides a detailed root-cause analysis and patch discussion; Makefile builds the kernel module; poc.c implements the PoC. The LICENSE is a research-use disclaimer. Exploit behavior: poc.c is a Linux kernel module for x86_64 guests. It supports both Intel and AMD paths via a module parameter (amd=1 for AMD, default Intel). It allocates pages, constructs nested page tables and guest memory structures, manipulates VMX/SVM state, and launches multiple kernel threads with roles such as writer, faulter, and optional flooders. These threads race nested virtualization activity to force the vulnerable host shadow MMU logic into reusing a child shadow page with the wrong role, eventually leading to rmap corruption and a host BUG/panic in pte_list_remove(). The code includes tunable parameters such as nvcpu, dwell, run_ms, diag, and nflood. Targeting: the exploit targets Linux KVM/x86 on Intel VMX/EPT and AMD SVM/NPT where nested virtualization causes the legacy shadow MMU path to be exercised. The documentation states the affected range spans from commit 2032a93d66fa to fix commit 81ccda30b4e8. It is specifically a hypervisor escape/DoS primitive from a guest VM, and the README notes that on systems exposing /dev/kvm as world-writable, the same bug class could also be adapted into a local privilege escalation scenario. Assessment: this is a legitimate exploit PoC, not a detector or fake sample. It is best classified as POC maturity because it provides a concrete trigger and impact (host panic) but does not ship the private full escape/RCE payload mentioned in the documentation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
257 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel KVM x86 shadow-paging use-after-free vulnerability caused by an unexpected role value. The advisory/plugin indicates exploits are available.
A vulnerability addressed by Ubuntu USN-8715-1; no technical flaw description is provided.
A known Linux kernel vulnerability used in a controlled demonstration to escape a Debian 12 VM. The AI agent reportedly developed its own exploit for the flaw.
A vulnerability referenced by the SUSE-SU-2026:3809-1 advisory; the supplied content does not provide technical details.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.