Security researcher Paulos Yibelo has announced the discovery of a full VM escape zero-day in Linux KVM, the hypervisor at the heart of many large-scale cloud deployments. The finding was made through Vercel’s bug bounty program, which targets vulnerabilities in its Sandbox product — an environment that uses Firecracker MicroVMs built atop KVM.
Vercel CEO Guillermo Rauch publicly acknowledged the severity, stating, “We’ve confirmed a KVM 0day through our Vercel Sandbox bounty program. Affecting the industry’s gold standard solution for Linux virtualization.” Neither Rauch nor Yibelo have released technical details, a silence that security experts say is prudent given the potential impact.
A guest-to-host escape would allow an attacker running a guest VM to take control of the entire host server and potentially access other virtual machines on the same hardware. The risk is magnified by KVM’s pervasiveness: AWS, Google Cloud, Nutanix, HPE, and Proxmox all rely on it. Firecracker, which uses KVM, is itself open source and widely adopted.
The Register notes that this follows the so-called 'Januscape' flaw earlier this year, another serious KVM vulnerability. Observers have suggested that Yibelo’s reward should exceed the $50,000 top payout in Vercel’s program, given the flaw’s gravity. A fix will likely require hot-patching KVM or live-migrating VMs from vulnerable hosts. Until more is disclosed, cloud operators and enterprise users are advised to monitor for updates.