{
  "id": 12294182,
  "title": "Security researcher claims they found KVM guest-host escape flaw",
  "url": "https://urgent.news/2026/10/06/security-researcher-claims-they-found-kvm-guest-host-escape-flaw",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-06T02:06:20.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/offbeat/2026/10/06/security-researcher-claims-they-found-kvm-guest-host-escape-flaw/5301267"
  },
  "original_language": "en",
  "account": "Security researcher Paulos Yibelo claims to have discovered a critical KVM guest-host escape vulnerability. The flaw allows a guest virtual machine to escape its container and gain root access on the host system. Yibelo received a bounty from Vercel for discovering the exploit. Vercel uses Firecracker MicroVMs, which rely on Linux KVM, as part of their sandbox solution for AI agents. The bug vulnerability affects the industry-standard Linux virtualization solution KVM. Notable cloud providers like AWS, Google, Nutanix, HPE, and Proxmox also rely on KVM. The discovery of this escape flaw is particularly concerning due to its potential impact on multiple guests on a single server, as well as the prevalence of KVM in public cloud infrastructure and enterprise virtualization. Responsible disclosure is crucial to prevent potential damage. If a fix is found, implementing it may require downtime. This is the second significant vulnerability discovered in KVM this year following the Januscape flaw. Critics argue Yibelo's reward should exceed the $50,000 available under Vercel's bug bounty program.",
  "summary": "Firecracker MicroVMs, which started at AWS, seem to be the problem",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Security researcher claims they found KVM guest-host escape flaw",
        "url": "https://urgent.news/2026/10/06/security-researcher-claims-they-found-kvm-guest-host-escape-flaw-12296393",
        "published": "2026-10-06T02:06:20.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}