Researcher claims full KVM guest-to-host escape flaw
Security researcher Paulos Yibelo reported a 0-day full guest-to-host root escape in Linux KVM, confirmed via Vercel's Sandbox bug bounty. Vercel's Sandbox runs on Firecracker MicroVMs, which rely on KVM; no technical details are public yet.
- Flaw allows escape from guest VM to host root
- Bug confirmed through Vercel Sandbox bounty program
- KVM powers AWS, Google, Nutanix, HPE and Proxmox
- Vercel bounty caps rewards at $50,000
Read next
Security