ESPN DeportesRays arma rally y pone contra la pared a Yankees en SDLAThe Jerusalem PostIsrael must be ready for any threat, no matter how unthinkable it may seem - editorialInquirerImpeachment court opens VP Duterte’s P4.4-B transaction docsESPNBijan Robinson, Falcons make NFC South statement in rout of SaintsZDF heuteEntdecken Sie das ZDF-NachrichtenstudioCNN TürkHava Durumu (06-10-2026)Sky TG24Guerra Ucraina Russia, nella notte centinaia di droni sulla regione di Mosca. LIVESözcüAkaryakıt devinde deprem: Benzin zammı şirketi sarstı, CEO görevi bıraktıCapital FMEthiopian rebel forces withdraw from Tigray regional capitalRapplerAccenture contractor removed from FBI following damaging data breach, sources sayn-tv44 Mann - und nun?: Klopps erschreckendste Erkenntnis könnte die Neustart-Chance seinSRF NewsTrockenheit und Futternot – Wenn das Futter knapp wird: Mehr Tiere in der Auktion
The Daily Newsstand · Free, Always
Tuesday, October 6, 2026

Security researcher claims to they found KVM guest-host escape flaw

Translate

Firecracker MicroVMs, which started at AWS, seem to be the problem

Linux KVM, the hypervisor favoured by hyperscale clouds, apparently has a full VM escape bug.

That nasty news came from security researcher Paulos Yibelo, who on X shared a screenshot of a bug bounty award he won for discovering what he described as “Full VM escape zeroday (guest>host root in industry standard hypervisors)!”

The bug bounty Yibelo participated in is run by Vercel, a company that provides MicroVMs as sandboxes for AI agents to work inside. The company’s Sandbox uses Firecracker MicroVMs, a technology created by AWS, which relies on Linux KVM – the kernel level hypervisor in Linux.

REG AD

Vercel CEO Guillermo Rauch named KVM as the hypervisor identified by Yibelo.

REG AD

“We’ve confirmed a KVM 0day through our Vercel Sandbox bounty program. Affecting the industry’s gold standard solution for Linux virtualization,” he wrote.

And that’s all the info that has made it into the public view at this time. The Register can find no chat on relevant mailing lists. We have asked Rauch and Yibelo for additional details.

Hopefully, we don’t hear from either of them for days or weeks, for two reasons.

One is that guest-host escapes are the nightmare virtualization scenario because they mean whoever runs a guest VM could take over an entire server, and perhaps gain the ability to control other guests.

The other is that KVM is astoundingly prevalent: AWS and Google both use it to power their public clouds. Enterprise virtualization players Nutanix, HPE, and Proxmox also rely on KVM. And of course KVM is also in Firecracker, which is open source and could therefore be running in all sorts of places.

Whatever Yibelo discovered therefore very much needs a responsible disclosure process, because if hints about the flaw emerge it could allow attackers to do a lot of damage.

Once a fix is found, the next question is whether implementing it will require disruption or downtime. It’s possible to hot-patch KVM, and to migrate live VMs from vulnerable hosts to machines running a patched version of Linux. Hopefully those techniques will work.

This might be the second nasty bug discovered in KVM this year, after the so-called Januscape flaw.

REG AD

Beyond the potential risks this bug created, observers have suggested the potential seriousness of the flaw means Yibelo’s reward should exceed the $50,000 available under Vercel’s bug bounty program. ®

View the original on The Register →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.