- Sources: Trail of Bits, HN 49450188
- Summary: Trail of Bits ran GPT-5.6-Cyber against a QEMU/KVM VM hosted on a Debian 12 dev machine and reports three distinct escapes, while a Firecracker sandbox held. The first hit the host kernel through CVE-2026-53359, named Januscape, and the second used the libslirp 4.7.0 that Debian 12 ships, carrying CVE-2026-9539, combined with an unmarked bugfix commit. Before the third the author rebuilt libslirp and QEMU from upstream, and the agent still chained three 0-days with one KVM bug patched upstream but absent from the distribution kernel: a QEMU VAPIC unchecked ROM alias overlapping locked SMRAM, an unsynchronized shadow page, a stale level-2 role in
paging64_invlpg, and a libslirp mixed-fragment-IHL ICMP reassembly bug. - Why it matters: An ordinary VM is no longer a sufficient boundary for a capable coding agent, and the report concludes that the machine doing the sandboxing needs a rapidly updating distribution rather than a slow-moving stable one.
send feedback on this story