Detalle de la noticia

Vulnerabilidad

Security researcher claims they found KVM guest-host escape flaw

Fuente: The Register - Security Publicado: 06/10/2026 · 02:06 UTC
Compartir:
Vulnerabilidad Security researcher claims they found KVM guest-host escape flaw
Imagen: The Register - Security

Linux KVM, the hy­per­vi­sor fa­vou­red by hy­pers­ca­le clouds, ap­pa­rently has a full VM es­ca­pe bug. That nasty news came from se­cu­rity re­sear­cher Pau­los Yi­be­lo, who on X sha­red a screenshot of a bug bounty award he won for dis­co­ve­ring what he des­cri­bed as “Full VM es­ca­pe ze­ro­day (guest>host root in in­dustry stan­dard hy­per­vi­sors)!” The bug bounty Yi­be­lo par­ti­ci­pa­ted in is run by Ver­cel, a com­pany that pro­vi­des Mi­croVMs as sand­bo­xes for AI agents to work in­si­de. The com­pany’s Sand­box uses Fi­re­crac­ker Mi­croVMs, a tech­no­logy crea­ted by AWS, which re­lies on Linux KVM – the ker­nel level hy­per­vi­sor in Linux. Ver­cel CEO Gui­ller­mo Rauch named KVM as the hy­per­vi­sor iden­ti­fied by Yi­be­lo. “We’ve con­fir­med a KVM 0day th­rough our Ver­cel Sand­box bounty pro­gram. Af­fec­ting the in­dustry’s gold stan­dard so­lu­tion for Linux vir­tua­li­za­tion,” he wrote. And that’s all the info that has made it into the pu­blic view at this time. The Re­gis­ter can find no chat on re­le­vant mai­ling lists. We have asked Rauch and Yi­be­lo for ad­di­tio­nal de­tails. Ho­pe­fully, we don’t hear from either of them for days or weeks, for two reasons. One is that guest-host es­ca­pes are the night­ma­re vir­tua­li­za­tion sce­na­rio be­cau­se they mean whoe­ver runs a guest VM could take over an en­ti­re ser­ver, and perhaps gain the abi­lity to con­trol other guests. The other is that KVM is as­toun­dingly pre­va­lent: AWS and Goo­gle both use it to power their pu­blic clouds. En­ter­pri­se vir­tua­li­za­tion pla­yers Nu­ta­nix, HPE, and Prox­mox also rely on KVM. And of cour­se KVM is also in Fi­re­crac­ker, which is open sour­ce and could the­re­fo­re be run­ning in all sorts of pla­ces. Wha­te­ver Yi­be­lo dis­co­ve­red the­re­fo­re very much needs a res­pon­si­ble dis­clo­su­re pro­cess, be­cau­se if hints about the flaw emer­ge it could allow at­tac­kers to do a lot of da­ma­ge. Once a fix is found, the next ques­tion is whether im­ple­men­ting it will re­qui­re dis­rup­tion or down­ti­me. It’s pos­si­ble to hot-patch KVM, and to mi­gra­te live VMs from vul­ne­ra­ble hosts to ma­chi­nes run­ning a pat­ched ver­sion of Linux. Ho­pe­fully those tech­ni­ques will work. This might be the se­cond nasty bug dis­co­ve­red in KVM this year, after the so-ca­lled Ja­nus­ca­pe flaw. Be­yond the po­ten­tial risks this bug crea­ted, ob­ser­vers have sug­ges­ted the po­ten­tial se­rious­ness of the flaw means Yi­be­lo’s re­ward should ex­ceed the $50,000 avai­la­ble under Ver­cel’s bug bounty pro­gram. ®…