Independent Vuln. Researcher / Pwn2Own Berlin 2025, 2026 / Google kernelCTF 0-day / Google kvmCTF 0-day / Pwnie Awards 2025, 2026

🤔
Orphaned VMs: Running VMs Uninterrupted While Host Kernel Is Offline For Reboots/Updates Next level craziness out of Google!! Keeping the VMs running while the host kernel is down for live updates. Experimental Linux patches posted. phoronix.com/news/Orphaned-V…
2
11
3,214
Another month, another KVM escape. Patch if you're affected. openwall.com/lists/oss-secur…
3
21
112
9,397
Won Best RCE and Best PE at the Pwnie Awards 2026 🏆🏆 Three of my projects were nominated this year, and ITScape and Dirty Frag took home the awards. That makes three Pwnies in total, following last year’s Best PE. Pwnie is probably the award that motivates me the most. Next year’s goal: find a vuln that destroys the world ;) Thank you, @PwnieAwards!
7
19
191
16,012
Thanks to @_qwerty_po for accepting the awards on my behalf while I was sick.
11
1,717
💥 Introducing "Zapscape" (CVE-2026-64561) A Guest-to-Host Escape in KVM/x86 exploiting a UAF in the shadow MMU's recursive "ZAP" path. Can escape to the host on x86 public clouds that expose nested virtualization. A separate vulnerability from Januscape. If you match the vulnerable conditions, apply the patch immediately. Details: zapscape.io
5
75
360
31,196
This completes the KVM Escape Trilogy. Hopefully there will be no sequel :/
1
21
1,651
Interesting.
Nous avons terminé la compagne de patching du jbug critique CVE-2026-53359 dans KVM. Vu le niveau critique du bug, nous n'avons pas communiqué avant de démarrer le patching, il fallait aller vite. Maintenant que l'infra est en sécurité, voici le REX. blog.ovhcloud.com/campagne-d…
12
5,872
"Januscape" only triggers on Intel and AMD hosts, but if you still haven't patched "ITScape", your arm64-based hosts are at risk too, so apply the patch promptly.
🚨 Introducing "ITScape" (CVE-2026-46316) A Guest-to-Host Escape in KVM/arm64. Guest-side actions alone exploit a use-after-free to run root-privileged code in the host kernel. Unlike the commonly published QEMU escapes, the bug lives in in-kernel KVM, not QEMU. On a successful exploit, commands run with host kernel privilege rather than the privilege of a user process, threatening the guest-host isolation of multi-tenant arm64 public clouds. To the best of public knowledge, the first Guest-to-Host Escape Exploit targeting in-kernel KVM/arm64. Details: itscape.io
1
10
5,960
Anyway, this wraps up my cute tux series. The face is especially funny, isn't it? lol - Dirty Frag: Universal Linux LPE - ITScape: The first Guest-to-Host Escape in KVM/arm64 - Januscape: The first Guest-to-Host Escape in KVM/x86 && Google kvmCTF 0-day exploit
Made with AI
2
1
23
3,158
💥 Introducing "Januscape" (CVE-2026-53359) A Guest-to-Host Escape in KVM/x86 exploiting a UAF in the shadow MMU. Triggerable on both Intel and AMD hosts. Threatens x86 public clouds (GCP, AWS) that expose nested virtualization. "16 years" latent. Successfully used as a 0-day exploit in "Google kvmCTF". To the best of public knowledge, the first KVM exploit research triggerable on both Intel and AMD. Details: januscape.io
7
104
452
62,163
🚨 Introducing "ITScape" (CVE-2026-46316) A Guest-to-Host Escape in KVM/arm64. Guest-side actions alone exploit a use-after-free to run root-privileged code in the host kernel. Unlike the commonly published QEMU escapes, the bug lives in in-kernel KVM, not QEMU. On a successful exploit, commands run with host kernel privilege rather than the privilege of a user process, threatening the guest-host isolation of multi-tenant arm64 public clouds. To the best of public knowledge, the first Guest-to-Host Escape Exploit targeting in-kernel KVM/arm64. Details: itscape.io
4
93
310
36,749
The patch addressing several Dirty Frag variants has been merged into netdev tree. Details: seclists.org/oss-sec/2026/q2…
18
2,878
Well... not a bad result, considering I got the last slot 😜
Confirmed! Hyunwoo Kim (@v4bel) chained a use-after-free and uninitialized memory bug to escalate privileges on Red Hat Enterprise Linux for Workstations in the fourth round, earning $5,000 and 2 Master of Pwn points. #Pwn2Own #P2OBerlin
8
1
84
9,671
Success! Hyunwoo Kim (@v4bel) was able to exploit Red Hat Enterprise Linux for Workstations! If confirmed, they win $20,000 and 2 Master of Pwn points. They're off to the disclosure room to explain how they did it. #Pwn2Own #P2OBerlin
3
40
7,304
This bug is a variant path that became active after one of the "Dirty Frag" patches, "f4c50a4034e6". The actual window of vuln is only about "9 days", and creation of an unpriv userns is a prerequisite. To distros and Linux users: the patch proposed in the referenced write-up still does not cover at least one variant, __pskb_copy_fclone, so applying that patch alone does not prevent LPE. I have submitted a follow-up patch addressing this additional variant: lore.kernel.org/all/agRfuVOe… I'm also accelerating further analysis and testing on my end. I'll post updates as more results come in.
another day, another universal linux LPE
3
20
136
21,330
I recommend keeping the Dirty Frag mitigation enabled for the time being.
6
2,410