Security researchers found a flaw in a widely used Linux virtualization tool that gives a guest user a path to take over the physical hardware from within a virtual machine. Vercel confirmed the zero-day vulnerability in the Kernel-based Virtual Machine (KVM), which permits a full VM escape from guest to host root, after Paulos Yibelo and other researchers identified the issue through the company's Sandbox bounty program.

The vulnerability impacts a tool described as the industry's gold standard for Linux virtualization, and experts warn that the blast radius of the bug is huge. Vercel is using the discovery to harden the sandbox environment for its AI agents and will publish a full technical writeup of the exploit.

Content history (1)
  • 2026-10-04 · Summary · vi · Wording fix
    Vercel đã xác nhận một lỗ hổng bảo mật 0day trong hệ thống KVM, cho phép kẻ tấn công trốn…
    Các nhà nghiên cứu bảo mật tìm thấy một lỗ hổng trong công cụ ảo hóa Linux được dùng rộng…
Sign in to suggest edits

Key sources

  1. SOURCE@rauchg“confirmed a KVM 0day through our Vercel Sandbox bounty program. Affecting the industry’s gold standard solution for Linux virtualization”x.com
  2. SOURCE@paulosyibelo“Full VM escape zeroday (guest>host root in industry standard hypervisors)!”x.com
  3. SUPPORT@s1r1u5_“this is quiet bad!! the blast raidus of the bug is huge”x.com
  4. SOURCEhuggingnewshuggingnews.com
Markdown