Urgent.News

What's breaking now, across thousands of outlets.

Tech

Security researcher claims they found KVM guest-host escape flaw

Firecracker MicroVMs, which started at AWS, seem to be the problem

Security researcher claims they found KVM guest-host escape flaw

Security researcher Paulos Yibelo claims to have discovered a critical KVM guest-host escape vulnerability. The flaw allows a guest virtual machine to escape its container and gain root access on the host system. Yibelo received a bounty from Vercel for discovering the exploit. Vercel uses Firecracker MicroVMs, which rely on Linux KVM, as part of their sandbox solution for AI agents.

The bug vulnerability affects the industry-standard Linux virtualization solution KVM. Notable cloud providers like AWS, Google, Nutanix, HPE, and Proxmox also rely on KVM. The discovery of this escape flaw is particularly concerning due to its potential impact on multiple guests on a single server, as well as the prevalence of KVM in public cloud infrastructure and enterprise virtualization.

Responsible disclosure is crucial to prevent potential damage. If a fix is found, implementing it may require downtime. This is the second significant vulnerability discovered in KVM this year following the Januscape flaw. Critics argue Yibelo's reward should exceed the $50,000 available under Vercel's bug bounty program.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

I have completely abandoned MicroFeed.

Github因为我发的一些比基尼的图片直接给我删库了,其实用的也不是GitHub的图床了还是被废了。虽然GitHub/GitLab注册很简单,但对这些第三方代码平台有点烦了。 SaaS全托管的最后考虑Mataroa…

More from Tuesday 6 October →