Vercel Confirms KVM Zero-Day in Firecracker Sandboxes
Vercel confirmed a Linux KVM zero-day in Firecracker sandboxes reported by Paulos Yibelo; one outlet says it paid $50,000, and no CVE or patch is public.
Vercel confirmed a Linux KVM zero-day reported by security researcher Paulos Yibelo through its Sandbox bug bounty; he describes it as a full guest-to-host virtual machine escape that yields root on the host. Cyber Security News reports that Vercel paid its $50,000 Sandbox bounty maximum for a live proof of concept and that CEO Guillermo Rauch said a technical write-up will follow. The Register reports Rauch’s confirmation and Yibelo’s bounty claim but does not state the dollar amount, and it says no proof of concept is public. Vercel Sandbox runs AI-agent workloads, with each sandbox in its own AWS-originated Firecracker microVM on KVM on bare-metal Amazon EC2, treating the microVM as the main security boundary. No source reports a CVE, affected versions, exploit chain, patch, or mailing-list discussion, and statements do not show customer data access or widespread exploitation; The Register says exploitation has not been reported. The Register also notes that KVM underpins AWS, Google, Nutanix, HPE, and Proxmox, and recalls Januscape as another serious KVM bug found this year.
- Researcher Paulos Yibelo reported a Linux KVM flaw that he describes as a full guest-to-host escape yielding root on the host.
- Vercel CEO Guillermo Rauch said the company confirmed a KVM zero-day affecting Vercel Sandbox.
- Cyber Security News says Vercel paid its $50,000 Sandbox bounty maximum for a live proof of concept; The Register does not state the amount.
- Each sandbox runs in its own AWS-originated Firecracker microVM on KVM on bare-metal Amazon EC2; The Register says the product runs AI-agent workloads.
- No CVE, affected versions, public exploit chain, patch, or mailing-list discussion has been published.
- Available statements do not show customer data access or widespread exploitation; The Register says exploitation has not been reported.
- Rauch said a technical write-up will follow, according to Cyber Security News.
- The Register notes that KVM also underpins AWS, Google, Nutanix, HPE, and Proxmox, and recalls this year’s earlier Januscape KVM bug.
Coverage timelineoldest first · each row is one article
- · 5d agoVercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000
Cyber Security News· 74
Vercel confirmed researcher Paulos Yibelo's KVM zero-day guest-to-host root escape and paid a $50,000 bounty.
- · 3d agoSecurity researcher claims to they found KVM guest-host escape flaw
The Register · Security· 72
Researcher claims a KVM guest-to-host escape zero-day; Vercel confirmed it, but no details are public.
- · 3d agoSecurity researcher claims they found KVM guest-host escape flaw
The Register · Security· 78