OVH reveals semi-secret plan to fix critical Januscape bug with mass reboots – and an Australian crash-test dummy

https://image.theregister.com/225297.jpg?imageId=225297&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

French cloud backported a patch into Debian and didn’t seek customer consent, despite chance of downtime

French cloud operator OVH has revealed it used its Sydney, Australia, datacenter as the crash test dummy to test a rapid rollout of a fix for the critical Januscape guest-host escape bug in the Linux kernel-based virtual machine (KVM).

Januscape, aka CVE-2026-53359, allowed attackers with root access to a guest VM to execute code as root on the host, crash that machine, or take over all other guest VMs.

A widespread guest-host escape exploitation is a nightmare scenario, because many major clouds use KVM to slice their servers into virtual machines and then rent those guests to clients. The prospect of attackers accessing one tenant’s VM and using it to crash other guests or an entire host is therefore a terrifying violation of cloud operators’ promise to run customer workloads in splendid isolation.

Fixing...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE