16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

A serious vulnerability, dubbed 'Januscape,' in Linux's KVM hypervisor allows guest virtual machines to escape and compromise the host system on Intel and AMD x86 systems. This use-after-free bug corrupts the host kernel's shadow-page state, potentially leading to severe security breaches. The researcher behind the discovery has released a proof-of-concept that causes the host to panic, and hints at an even more dangerous, unreleased exploit. This flaw underscores the critical need for robust security measures in virtualized environments, especially given the widespread use of KVM across various platforms.

Original Source

Read the full article at Thehackernews →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.