Vercel confirms KVM zero-day that may let guests seize host root
Vercel has confirmed a KVM zero-day reported through its Sandbox bug bounty program, with researcher Paulos Yibelo claiming it enables a virtual machine to escape and gain root access on its host. Vercel Sandbox runs Firecracker microVMs on KVM, but the vulnerability’s technical details and affected versions have not been made public. There is not yet enough information to determine which KVM deployments are affected or what fix administrators should apply.
Source
👉@sysadminoff
https://4sysops.com/archives/vercel-confirms-kvm-zero-day-that-may-let-guests-seize-host-root/
Post #20696
17
