Urgent.News

What's breaking now, across thousands of outlets.

Tech

Security researcher claims to they found KVM guest-host escape flaw

Firecracker MicroVMs, which started at AWS, seem to be the problem

Security researcher claims to they found KVM guest-host escape flaw

Security researcher Paulos Yibelo claims to have discovered a critical vulnerability in Linux KVM, a hypervisor commonly used in large-scale cloud computing. Yibelo shared the news on X, revealing he won a bug bounty award for finding a "Full VM escape zeroday" that grants guest host root privileges within industry-standard hypervisors.

The vulnerability was identified while testing Vercel's MicroVM sandbox, which utilizes Firecracker MicroVMs developed by AWS and relies on Linux KVM. Vercel CEO Guillermo Rauch confirmed the bug, emphasizing that the flaw impacts the industry's leading Linux virtualization solution. The Register has not found any further details from Rauch or Yibelo on relevant mailing lists.

Guest-host escapes are particularly concerning, as they allow an attacker to take control of an entire server and potentially other guest VMs. KVM is widely used by major cloud providers like AWS and Google, as well as enterprise virtualization companies such as Nutanix, HPE, and Proxmox. Open-source Firecracker, which could be deployed in various systems, also relies on KVM.

Responsible disclosure is crucial to prevent potential damage. Once a fix is available, implementing it may require minimal disruption or downtime, as hot-patching KVM and migrating live VMs to patched hosts are possible solutions. This vulnerability may be the second significant flaw discovered in KVM this year, following the Januscape flaw.

Experts suggest Yibelo's reward should exceed the $50,000 offered by Vercel's bug bounty program due to the bug's severity.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at theregister.com →

More in Tech

I have completely abandoned MicroFeed.

Github因为我发的一些比基尼的图片直接给我删库了,其实用的也不是GitHub的图床了还是被废了。虽然GitHub/GitLab注册很简单,但对这些第三方代码平台有点烦了。 SaaS全托管的最后考虑Mataroa…

More from Tuesday 6 October →