OVH reveals semi-secret plan to fix critical Januscape bug with mass reboots – and an Australian crash-test dummy

← Back to the feed

OVH reveals semi-secret plan to fix critical Januscape bug with mass reboots – and an Australian crash-test dummy

The Register · 13 hours ago

OVH has disclosed how it patched Januscape (CVE-2026-53359), a critical guest-host escape flaw in the Linux KVM hypervisor that could let an attacker with root access to a virtual machine take control of the host server or hijack other tenants' VMs. Because such a bug threatens the isolation clouds promise customers, the French provider treated it as an emergency, rejecting safer but slower fixes in favour of backporting a patch into its production Debian build and rebooting affected hosts without seeking individual customer consent, accepting that some single-host customers would suffer downtime.

OVH's CISO Julien Levrard detailed the response, which covered tens of thousands of hosts running roughly a million virtual machines. The firm ruled out disabling nested virtualisation, live patching and live migration as impractical or too slow, and chose mass reboots instead, deliberately staying quiet about the plan while systems remained unpatched to avoid tipping off attackers. It first trialled the rollout in its smaller Sydney datacentre, timed to fall during European working hours but a quiet period locally, with reboot waves halted automatically if 15 hosts failed at once in dense regions, or five elsewhere.

  • OVH patched a critical KVM guest-host escape bug called Januscape.
  • It rebooted hosts en masse without asking customer permission first.
  • Sydney was used as a test region before the wider rollout.

Business Markets

Read the full article at the source →