Security researcher claims to they found KVM guest-host escape flaw
Researcher claims a KVM guest-to-host escape zero-day; Vercel confirmed it, but no details are public.
Security researcher Paulos Yibelo says he won a Vercel bug bounty for a full guest-to-host root escape in industry-standard hypervisors. Vercel CEO Guillermo Rauch said the company confirmed a Linux KVM zero-day affecting Vercel Sandbox, which uses AWS Firecracker MicroVMs on KVM. No CVE, exploit details, or patch have been published, and The Register found no related mailing-list discussion. KVM is widely used by AWS, Google, Nutanix, HPE, and Proxmox; the article also recalls the earlier Januscape KVM bug.