Security researcher claims they found KVM guest-host escape flaw
Firecracker MicroVMs, which started at AWS, seem to be the problem
Linux KVM, a widely-used hypervisor in cloud computing, has allegedly been compromised by a critical flaw, according to security researcher Paulos Yibelo. Yibelo disclosed the vulnerability through a bug bounty program run by Vercel, a company that provides MicroVMs as sandboxes for AI agents. The Firecracker MicroVM technology, developed by Amazon Web Services, relies on KVM, making this a significant concern for the industry.
Vercel's CEO, Guillermo Rauch, confirmed the KVM 0day identified by Yibelo, describing it as a "full VM escape zeroday" that allows a guest VM to gain root access in an industry-standard hypervisor. The incident highlights the vulnerability of KVM, which is used by major cloud providers like AWS and Google, as well as enterprise virtualization platforms such as Nutanix, HPE, and Proxmox.
The flaw could potentially enable attackers to take control of entire servers and other virtual machines. Responsible disclosure of the vulnerability is crucial to prevent potential damage. Implementing a fix may require downtime, but hot-patching and live migration techniques could mitigate this issue. This may mark the second significant bug discovered in KVM this year, following the Januscape flaw.
Some experts suggest that Yibelo's reward should exceed the $50,000 limit set by Vercel's bug bounty program due to the severity of the flaw.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Security researcher claims they found KVM guest-host escape flaw theregister.com