news.mlab.sh
Back to the feed
vulnerability

Security researcher claims to they found KVM guest-host escape flaw

Medium
Image: The Register
Summary

A security researcher, Paulos Yibelo, discovered a ‘Full VM escape zeroday’ in Linux KVM, the hypervisor used by companies like Vercel and AWS. The Vercel Sandbox program, utilizing AWS’s Firecracker MicroVMs based on KVM, is affected. The article indicates that a fix is needed and migration of VMs may be required.

Read the full article at The Register

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.