vulnerability
Security researcher claims to they found KVM guest-host escape flaw
Medium
Summary
A security researcher, Paulos Yibelo, discovered a ‘Full VM escape zeroday’ in Linux KVM, the hypervisor used by companies like Vercel and AWS. The Vercel Sandbox program, utilizing AWS’s Firecracker MicroVMs based on KVM, is affected. The article indicates that a fix is needed and migration of VMs may be required.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data