Hi all,
As you can tell from the subject, we're back again having shipped patched kernels to the testing repository for two serious Linux kernel vulnerabilities and are asking the community to help verify them before they move to production.
Januscape (CVE-2026-53359) is a KVM/x86 flaw affecting all supported releases (8, 9, and 10), on both Intel and AMD. In its most serious form it is a guest-to-host escape: an attacker who can start a VM can break out and run commands as root on the host, which puts nearly every multi-tenant x86 cloud host at risk. It can also crash the host kernel from inside a guest (DoS), and because /dev/kvm is world-readable at 0666 by default, it doubles as a local privilege escalation to root with no VM involved. The bug went undetected for roughly 16 years and is now patched in mainline.
Bad Epoll (CVE-2026-46242) is a use-after-free race in the kernel's epoll subsystem that gives an unprivileged local user a reliable escalation to root. It affects AlmaLinux 9 and 10 (8 is not affected).
AlmaLinux's core team backported both fixes to every affected branch, and ALESCo approved shipping ahead of the CentOS Stream / RHEL update.
How to test:
sudo dnf install -y almalinux-release-testing
sudo dnf update 'kernel*' --enablerepo=almalinux-testing
sudo reboot
uname -r && rpm -q kernel
Patched kernel versions (install this or higher):
AlmaLinux 8: kernel-4.18.0-553.139.4.el8_10 (Januscape only)
AlmaLinux 9: kernel-5.14.0-687.20.3.el9_8
AlmaLinux 10: kernel-6.12.0-211.30.3.el10_2
Disable the testing repo afterward on any production system:
sudo dnf config-manager --disable almalinux-testing
Report any problems in AlmaLinux
chat or at
bugs.almalinux.org. The kernels will move to production once the community has helped verify them.
--
Jonathan Wright
AlmaLinux OS Foundation