OVHcloud patches KVM flaw across tens of thousands of hosts
OVHcloud
· July 20, 2026
· ✓ verified
OVHcloud has announced that it conducted an emergency, controlled patching campaign to remediate CVE-2026-53359 across its KVM-based VPS and Public Cloud fleet.
- The company says it chose a backport patch + reboot strategy after evaluating alternatives such as waiting for vendor kernels, live patching, disabling nested virtualization, and live migration only.
- The operation was run follow the sun over 24/7 coordination, with a Go/No-Go approved by the COMEX and the first region treated in Sydney on 8 July.
- OVHcloud says the scope covered tens of thousands of hypervisor hosts and around one million virtual machines, with anti-affinity, stop thresholds (15 hosts in dense regions, 5 elsewhere), and selective live migration for sensitive workloads.
- The article also describes operational incidents during the campaign, including libvirt-guests conflicts, API deadlocks in Paris, support saturation in BHS, and a later manager banner/status page rollout for customer communication.