OVHcloud patches KVM vulnerability across global fleet
OVHcloud
· July 20, 2026
· ✓ verified
OVHcloud has described its emergency response to CVE-2026-53359, a KVM x86 use-after-free vulnerability, including a fleet-wide patch-and-reboot campaign across its global hypervisor hosts.
- The company chose unilateral patching with controlled impact and backported the fix to its Debian production kernels, then rolled out patch + reboot waves across tens of thousands of hosts hosting around one million virtual machines.
- The operation began in Sydney on Wednesday, July 8, then followed the sun across regions; OVHcloud also used live migration for sensitive workloads, set stop thresholds of 15 hosts in high-density regions and 5 hosts elsewhere, and reported issues such as VM restart conflicts, API deadlocks, and support saturation during the campaign.