# Any news on when a fixed release for Januscape (CVE-2026-53359), the KVM/x86 guest-to-host escape vulnerability, will be available?

**URL:** https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658
**Category:** Rocky Linux Help & Support
**Created:** [July 8, 2026, 6:39am UTC](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658 "2026-07-08T06:39:47Z")
**Posts on this page:** 16
**Page:** 2

<div class="post-metadata">

### Author: ![PF92](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@PF92](https://forums.rockylinux.org/u/PF92)
#### Post date: [July 13, 2026, 3:35pm UTC](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658/21 "2026-07-13T15:35:01Z")

</div>

> [@jabuzzard](#):
>
> Noting that if LPE’s are your problem, then GhostLock (CVE-2026-43499) has hit. No mitigation; root using the public exploit with 97% reliability in 5s and affects everything from RHEL6 through RHEL10, so basically everything. No patches yet from Red Hat. Debian Trixie and Ubuntu 26.04 do have updates, but not a lot else.

This is a problem for anyone running publicly accessible web applications (or other kinds of applications) because any attacker who has previously gained shell access through bugs in some code without exposing their presence can now elevate to root.

According to [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2026-43499), trixie and bookworm have been patched (bookworm on [3 July](https://lists.debian.org/debian-lts-announce/2026/07/msg00006.html)). The vulnerability was publicly announced on [7 July](https://nebusec.ai/research/ionstack-part-2/). AlmaLinux 10, 9 and 8 were patched on [9 July](https://almalinux.org/blog/2026-07-09-ghostlock/). RHEL 10 - only a few hours ago ([13 July](https://access.redhat.com/errata/RHSA-2026:38492)). RHEL 9 and 8 haven’t been patched yet. As I’ve already said on the Mattermost chat I can’t seriously consider RHEL, much less Rocky Linux, for any server instance that I will set up in the future.

---

<div class="post-metadata">

### Author: ![mashcraft](https://avatars.discourse-cdn.com/v4/letter/m/9de0a6/32.png) [@mashcraft](https://forums.rockylinux.org/u/mashcraft)
#### Post date: [July 13, 2026, 3:40pm UTC](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658/22 "2026-07-13T15:40:35Z")

</div>

If you check RHEL, the same is also true. Patches for RHEL 10 and RHEL 9 were released on July 8. Patches for RHEL 8 are not available. Red Hat [cve-details](https://access.redhat.com/security/cve/cve-2026-53359) . Rocky 10 and Rocky 9 patches were released a few days later on July 11 and July 12. Rocky 8 will not get patches until a few days after RHEL 8.

---

<div class="post-metadata">

### Author: ![jabuzzard](https://avatars.discourse-cdn.com/v4/letter/j/7993a0/32.png) [@jabuzzard](https://forums.rockylinux.org/u/jabuzzard)
#### Post date: [July 13, 2026, 4:04pm UTC](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658/23 "2026-07-13T16:04:37Z")

</div>

> [@PF92](#):
>
> I’ve already said on the Mattermost chat I can’t seriously consider RHEL, much less Rocky Linux, for any server instance that I will set up in the future.

My problem is I have a six-figure storage system for our HPC that mandates the use of a RHEL-based distribution. I tried mixing in Ubuntu for complex reasons around broken DFS support in the kernel CIFS driver from some time shortly after 3.10 and not fixed till 6.8 last year, and it didn’t work, and I was told in no uncertain terms not to mix distributions in GPFS.

While I agree LPEs are not great, as they can be chained with other vulnerabilities, in HPC we are particularly exposed because, by the very nature of what we are doing, users have shell access by design, so there is no need to chain in another vulnerability.

---

<div class="post-metadata">

### Author: ![PF92](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@PF92](https://forums.rockylinux.org/u/PF92)
#### Post date: [July 13, 2026, 5:32pm UTC](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658/24 "2026-07-13T17:32:38Z")

</div>

In your case AlmaLinux would probably be a good choice, its developers seem to care a lot about this group of users, which also includes shared hosting providers. You’ve also mentioned Oracle Linux, but I don’t know if it has ever released security updates ahead of RHEL like AlmaLinux has done?

My very first server was running Debian Etch, it was about 20 years ago, but later I got to like CentOS more, at least on servers. Now I’m seriously considering a return to Debian.

---

<div class="post-metadata">

### Author: ![jabuzzard](https://avatars.discourse-cdn.com/v4/letter/j/7993a0/32.png) [@jabuzzard](https://forums.rockylinux.org/u/jabuzzard)
#### Post date: [July 13, 2026, 7:06pm UTC](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658/25 "2026-07-13T19:06:32Z")

</div>

Oracle Linux has two kernel options: your standard Red Hat compatible kernel (RHCK) and an alternative Unbreakable Enterprise Kernel (UEK). This is completely different to the RHCK kernel; it’s 5.15-based rather than 5.14, on 9, and consequently Oracle patches it on a completely different time scale, independently of Red Hat, and frequently faster than Red Hat. Note that if you do a fresh install on Oracle Linux 9.6+, you will get a 6.12 based UEK instead, but the older 5.15 is still getting updates.

To be totally honest, if you need/want a RHEL-based distro and the RHEL kernel is lacking drivers you need, then Oracle Linux with the UEK is a really good choice because the UEK carries a _LOT_ more drivers than even the extended AlmaLinux kernel or, for that matter, bodging things with Elrepo.

The only issue with both Oracle Linux UEK and the extended AlmaLinux kernel is when it comes to needing kernel level compatibility and especially source code kernel compatibility. One of the reasons we switched from Alma to Rocky is that we had some issues building the GPFS kernel module on one of the “extended” AlmaLinux kernels. They did say they would regard that as a bug and fix it, but we decided to go with Rocky instead and sidestep that issue when upgrading from an RHEL8 base to an RHEL9 base. That, along with the Ansys support, was the deciding factor. That decision is now under reevaluation.

Personally, at home I use Oracle Linux because it has drivers for all the TV tuners for my Plex server that Red Hat ripped out in 9, along with a lot of image capture cards (without notification initially in the release notes) and seem to have added back in, in 10.2 (AI vision workloads, I imagine and entirely predictable when they ripped it all out).

---

<div class="post-metadata">

### Author: ![pospos369](https://avatars.discourse-cdn.com/v4/letter/p/54ee81/32.png) [@pospos369](https://forums.rockylinux.org/u/pospos369)
#### Post date: [July 14, 2026, 1:23am UTC](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658/26 "2026-07-14T01:23:57Z")

</div>

| [kernel-5.14.0-687.24.1.el9](https://dl.rockylinux.org/pub/rocky/9/BaseOS/x86_64/os/Packages/k/kernel-5.14.0-687.24.1.el9_8.x86_64.rpm "kernel-5.14.0-687.24.1.el9\_8.x86\_64.rpm") |
| --- |

The [5.14.0-687.24.1](https://dl.rockylinux.org/pub/rocky/9/BaseOS/x86_64/os/Packages/k/kernel-5.14.0-687.24.1.el9_8.x86_64.rpm "kernel-5.14.0-687.24.1.el9\_8.x86\_64.rpm") version has been resolved, and the repository has been updated.

---

<div class="post-metadata">

### Author: ![long.cheung](https://avatars.discourse-cdn.com/v4/letter/l/77aa72/32.png) [@long.cheung](https://forums.rockylinux.org/u/long.cheung)
#### Post date: [July 14, 2026, 5:47am UTC](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658/27 "2026-07-14T05:47:16Z")

</div>

hello how about el8? rocky8?

---

<div class="post-metadata">

### Author: ![PF92](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@PF92](https://forums.rockylinux.org/u/PF92)
#### Post date: [July 14, 2026, 7:13am UTC](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658/28 "2026-07-14T07:13:04Z")

</div>

Based on what you’ve said I think you should also consider paid CIQ support for Rocky Linux if your company budget allows it. The professional approach to fixing security bugs seems to be limited to CIQ and aimed at paying customers. What the rest of us get for free in Rocky Linux can only be described as subpar. (In my case I’m not getting paid for my effort or earning any money from it so of course I’m not going to pay for support.)

---

<div class="post-metadata">

### Author: ![PF92](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@PF92](https://forums.rockylinux.org/u/PF92)
#### Post date: [July 14, 2026, 8:44am UTC](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658/30 "2026-07-14T08:44:27Z")

</div>

RHEL has lost a lot of reputation by not providing important security updates on time, so I wouldn’t even use the free developer subscription, let alone a paid subscription. And it’s not okay that servers which are run not-for-profit can be vulnerable to exploits for a long time because they don’t pay for support. Such an attitude harms the Internet as a whole. Maintaining a Linux distribution is hard and if maintainers don’t have the manpower to provide security updates quickly then the purpose of such a distribution is questionable.

---

<div class="post-metadata">

### Author: ![Roxy](https://avatars.discourse-cdn.com/v4/letter/r/53a042/32.png) [@Roxy](https://forums.rockylinux.org/u/Roxy)
#### Post date: [July 14, 2026, 7:09pm UTC](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658/31 "2026-07-14T19:09:25Z")

</div>

Incidentally, I noticed 5.14.0-687.25.1 with the rtmutex LPE (“GhostLock”) fix was released by RHEL on 2026-07-13 and by Rocky less than a day later, so hopefully that means all the problems have been worked out. Keep up the good work. :catdancefast:

---

<div class="post-metadata">

### Author: ![PF92](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@PF92](https://forums.rockylinux.org/u/PF92)
#### Post date: [July 15, 2026, 5:53am UTC](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658/32 "2026-07-15T05:53:03Z")

</div>

Sure, let’s celebrate that Rocky Linux released an update about 30 hours after Red Hat, without caring that Red Hat released its updates 6-7 days after the vulnerability became known to the whole world, with exploit code and no mitigation available. A problem with RHEL updates was already noticed in May when the Rocky Security repo was created, but at the most important time of trial so far, this repo remained unused.

---

<div class="post-metadata">

### Author: ![long.cheung](https://avatars.discourse-cdn.com/v4/letter/l/77aa72/32.png) [@long.cheung](https://forums.rockylinux.org/u/long.cheung)
#### Post date: [July 15, 2026, 5:56am UTC](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658/33 "2026-07-15T05:56:53Z")

</div>

Does anyone know when this update will be released for Rocky Linux 8?

---

<div class="post-metadata">

### Author: ![PF92](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@PF92](https://forums.rockylinux.org/u/PF92)
#### Post date: [July 15, 2026, 6:10am UTC](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658/34 "2026-07-15T06:10:52Z")

</div>

I don’t know when it will be released, it can be found on Koji: [https://koji.rockylinux.org/koji/buildinfo?buildID=122000](https://koji.rockylinux.org/koji/buildinfo?buildID=122000)

But it hasn’t yet made it to staging ([https://dl.rockylinux.org/stg/rocky/8/BaseOS/source/tree/Packages/k/](https://dl.rockylinux.org/stg/rocky/8/BaseOS/source/tree/Packages/k/))

---

<div class="post-metadata">

### Author: ![long.cheung](https://avatars.discourse-cdn.com/v4/letter/l/77aa72/32.png) [@long.cheung](https://forums.rockylinux.org/u/long.cheung)
#### Post date: [July 16, 2026, 1:20am UTC](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658/35 "2026-07-16T01:20:45Z")

</div>

Hello,

When running `yum update` on Rocky 8, I can see that **kernel-4.18.0-553.144.1.el8\_10** is available for installation in the `baseos` repo.

However, there is no corresponding update announcement published on [https://errata.rockylinux.org/](https://errata.rockylinux.org/) yet.

Could you please confirm if this specific kernel release includes the fixes for **CVE-2026-43499** and **CVE-2026-53359**?

> **[Making sure you're not a bot!](https://koji.rockylinux.org/koji/buildinfo?buildID=122000)**

Thanks!

---

<div class="post-metadata">

### Author: ![PF92](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@PF92](https://forums.rockylinux.org/u/PF92)
#### Post date: [July 16, 2026, 5:36am UTC](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658/36 "2026-07-16T05:36:27Z")

</div>

The Koji page shows the changelog and you can search it to find that both CVE-2026-43499 and CVE-2026-53359 have been fixed.

```plaintext
* Thu Jul 09 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [4.18.0-553.143.1.el8_10]
- locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (Phil Auld) [RHEL-193334] {CVE-2026-53166}
- rtmutex: Use waiter::task instead of current in remove_waiter() (Phil Auld) [RHEL-193143] {CVE-2026-43499}

* Thu Jul 09 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [4.18.0-553.142.1.el8_10]
- KVM: x86: Fix shadow paging use-after-free due to unexpected role (Paolo Bonzini) [RHEL-192411] {CVE-2026-53359}
- KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (Aidan Wallace) [RHEL-186618] {CVE-2026-46113}
(...)

```

The errata page is [https://errata.rockylinux.org/RLSA-2026:39179](https://errata.rockylinux.org/RLSA-2026:39179) but it only shows security fixes between 143 and 144.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/1X/91b7219eec10e30013422e4df76c1d898711a5d5.svg) [@system](https://forums.rockylinux.org/u/system)
#### Post date: [September 14, 2026, 5:36am UTC](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658/37 "2026-09-14T05:36:50Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.

[Previous page](https://forums.rockylinux.org/t/any-news-on-when-a-fixed-release-for-januscape-cve-2026-53359-the-kvm-x86-guest-to-host-escape-vulnerability-will-be-available/20658.md?page=1)
