Researcher Claims Serious Escape Flaw in Linux KVM, the Hypervisor Behind Major Clouds
Security researcher Paulos Yibelo has shared a screenshot of a bug bounty award for what he describes as a full virtual machine escape in Linux KVM, the hypervisor used by many large cloud providers. Vercel, which runs the bounty program and uses Firecracker MicroVMs (a technology created by AWS that relies on KVM) to sandbox AI agents, has confirmed a KVM zero-day. Vercel's CEO said it was found through the company's Sandbox bounty program.
Very little is public so far. The Register found no discussion on relevant mailing lists and has asked both Vercel and the researcher for more detail. A guest-to-host escape is among the most feared virtualisation problems, because someone running one guest VM could potentially take over the whole server and perhaps reach other guests. KVM is widely used: AWS and Google rely on it for their public clouds, and Nutanix, HPE and Proxmox also use it. Firecracker is open source, so it could be running in many other places.
The Register notes that responsible disclosure matters here, because a leak could let attackers do serious damage. It also points out that KVM can be hot-patched and live VMs can be moved from vulnerable hosts to patched ones, which may limit downtime once a fix exists. This may be the second serious KVM flaw this year, following the so-called Januscape bug.