OVH Implements Mass Reboots to Address Januscape Vulnerability
OVH executed mass reboots across its datacenter in Sydney to remediate the critical Januscape bug affecting KVM. This approach aimed to mitigate risks of guest-host escape attacks that could compromise thousands of virtual machines.

OVH's recent fix for the Januscape vulnerability (CVE-2026-53359) involved a mass reboot of hosts across its Sydney datacenter, impacting approximately one million virtual machines. The company prioritized a backport fix in Debian over alternatives like nested virtualization disabling or live patching due to concerns of stability and prolonged vulnerability.
The reboot was executed in waves to maintain application resilience, with strict thresholds to prevent simultaneous failures. Despite some operational challenges, including VM restarts and API issues, the CISO noted the process minimized customer impact. Future kernel vulnerabilities are anticipated, prompting OVH to enhance its patching methodology.




Comments