{
  "id": 12296393,
  "title": "Security researcher claims they found KVM guest-host escape flaw",
  "url": "https://urgent.news/2026/10/06/security-researcher-claims-they-found-kvm-guest-host-escape-flaw-12296393",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-06T02:06:20.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/offbeat/2026/10/06/security-researcher-claims-they-found-kvm-guest-host-escape-flaw/5301267"
  },
  "original_language": "en",
  "account": "Linux KVM, a widely-used hypervisor in cloud computing, has allegedly been compromised by a critical flaw, according to security researcher Paulos Yibelo. Yibelo disclosed the vulnerability through a bug bounty program run by Vercel, a company that provides MicroVMs as sandboxes for AI agents. The Firecracker MicroVM technology, developed by Amazon Web Services, relies on KVM, making this a significant concern for the industry. Vercel's CEO, Guillermo Rauch, confirmed the KVM 0day identified by Yibelo, describing it as a \"full VM escape zeroday\" that allows a guest VM to gain root access in an industry-standard hypervisor. The incident highlights the vulnerability of KVM, which is used by major cloud providers like AWS and Google, as well as enterprise virtualization platforms such as Nutanix, HPE, and Proxmox. The flaw could potentially enable attackers to take control of entire servers and other virtual machines. Responsible disclosure of the vulnerability is crucial to prevent potential damage. Implementing a fix may require downtime, but hot-patching and live migration techniques could mitigate this issue. This may mark the second significant bug discovered in KVM this year, following the Januscape flaw. Some experts suggest that Yibelo's reward should exceed the $50,000 limit set by Vercel's bug bounty program due to the severity of the flaw.",
  "summary": "Firecracker MicroVMs, which started at AWS, seem to be the problem",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Security researcher claims they found KVM guest-host escape flaw",
        "url": "https://urgent.news/2026/10/06/security-researcher-claims-they-found-kvm-guest-host-escape-flaw",
        "published": "2026-10-06T02:06:20.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}