3 min Security

Potential VM escape puts KVM security under the microscope

Potential VM escape puts KVM security under the microscope

A security researcher claims to have found a vulnerability that lets a virtual machine access the underlying host. The discovery was made during research into Vercel Sandbox, which uses Firecracker and KVM. It is not yet clear whether the vulnerability actually lies within KVM itself.

Researcher Paulos Yibelo announced the discovery after receiving a reward through Vercel’s bug bounty program. He describes it as a full VM escape that allows a guest to gain root privileges on the host.

Vercel CEO Guillermo Rauch confirmed to The Register that his company identified a zero-day vulnerability through the program and explicitly linked it to KVM. However, technical details have not yet been published. As a result, it is not yet possible to determine exactly which layer of the virtualization stack the vulnerability resides in.

Firecracker on top of KVM

That distinction is important. Vercel uses Firecracker MicroVMs for its Sandbox. AWS originally developed Firecracker for lightweight virtualization, and it uses KVM on Linux. An attack that reaches the host from a Firecracker environment therefore does not automatically mean that a flaw in KVM itself is the cause.

The Register, which reported the discovery, has not yet found any further information about the vulnerability on relevant mailing lists. As far as is known, no CVE, technical security advisory, or patch is available yet.

If KVM itself is vulnerable, the consequences could be significant. KVM is a key component of the virtualization infrastructure used by AWS and Google, among others, and is also used in platforms from Nutanix, HPE, and Proxmox.

Details withheld for now

The lack of technical information is not unusual for a vulnerability of this category. A VM escape can breach a critical security boundary: code running within an isolated virtual machine could thereby gain access to the host system. In environments where different workloads share the same physical infrastructure, this is especially sensitive.

It therefore makes sense to work on a solution first before disclosing technical details. Another factor is how a potential patch might be rolled out. KVM supports hotpatching capabilities, while cloud providers can migrate workloads between hosts. Whether these techniques are applicable to this vulnerability depends on the exact cause.

For now, this is primarily a reason to monitor developments closely, but it is not yet appropriate to speak of a proven, widespread KVM vulnerability. To do so, it must first become clear exactly where Yibelo’s VM escape originates and which configurations are actually vulnerable.