16-Year-Old Linux KVM Vulnerability Lets Guest VMs Reach the Host on Intel and AMD x86

Colleagues, I would like to draw your attention to a cybersecurity issue: Linux KVM has disclosed a long-standing vulnerability, CVE-2026-53359.
A use-after-free flaw in the shadow MMU can allow a guest VM to affect the host. On Intel and AMD x86 platforms, this may trigger a system panic and, in the worst case, code execution on the host.
The issue is especially concerning where nested virtualization is enabled. A fix has already been released, so I recommend checking kernel updates and, if needed, disabling nested virtualization for untrusted guests.
Why this matters: a single compromised VM can put the entire host and other tenants at risk.
How do you secure your KVM hosts?
#cybersecurity #Linux #KVM #vulnerability

