New Januscape Linux Flaw Allows VM Escape
A 16-year-old Linux kernel bug just surfaced that lets attackers break out of VMs and run code on the host.
The flaw, called Januscape, lives in how the kernel handles certain memory operations. It affects Intel and AMD systems running virtualization. Attackers inside a guest VM can escalate to host-level execution.
Impacts kernels back to 2010. Hits hypervisors on servers and developer machines using KVM or similar setups on both CPU vendors.
The researcher released a PoC that triggers a host kernel panic, while the full guest-to-host escape exploit is being withheld.
