Full Report
Firecracker MicroVMs, which started at AWS, seem to be the problem
Analysis Summary
# Vulnerability: Potential KVM/Firecracker Guest-to-Host Escape
## CVE Details
* **CVE ID:** Pending (Currently identified as a Zero-Day)
* **CVSS Score:** Not yet assigned (Estimated **Critical** based on impact)
* **CWE:** Likely **CWE-824** (Access of Uninitialized Pointer) or **CWE-119** (Memory Corruption), though unconfirmed.
## Affected Systems
* **Products:** Linux Kernel-based Virtual Machine (KVM), Firecracker MicroVM.
* **Versions:** Specific versions are currently undisclosed to protect the disclosure process.
* **Configurations:** Environments utilizing KVM for virtualization and Firecracker MicroVM sandboxes (e.g., Vercel Sandbox, AWS Lambda, Fargate).
## Vulnerability Description
Based on initial reports from security researcher Paulos Yibelo and Vercel CEO Guillermo Rauch, the flaw is a **Full VM Escape**. This vulnerability allows an attacker with root privileges within a guest virtual machine to break out of the isolation layer and execute code on the underlying host operating system with root privileges. While the specific technical root cause is currently under embargo, the flaw impacts the "gold standard" KVM hypervisor and its implementation in lightweight virtualization technologies like Firecracker.
## Exploitation
* **Status:** PoC exists (demonstrated to Vercel bug bounty program); currently a Zero-Day. No evidence of widespread exploitation in the wild at this stage.
* **Complexity:** High (Requires sophisticated knowledge of hypervisor memory management).
* **Attack Vector:** Local (Launched from within a compromised or malicious guest VM).
## Impact
* **Confidentiality:** High (Total access to host memory and other guest VM data).
* **Integrity:** High (Ability to modify host kernel and system files).
* **Availability:** High (Ability to crash the host or shut down all co-resident VMs).
## Remediation
### Patches
* **Status:** No public patch is currently available. The flaw is undergoing a responsible disclosure process involving major stakeholders (likely including the Linux Kernel team and AWS).
### Workarounds
* **Isolation:** Limit the execution of untrusted code within KVM/Firecracker environments where possible until a patch is released.
* **Defense in Depth:** Ensure host systems are hardened to minimize the impact if an escape occurs (e.g., using SELinux/AppArmor in enforcing mode).
## Detection
* **Indicators of Compromise:** Unusual syscall activity originating from the hypervisor process, unexpected memory spikes on the host, or unauthorized attempts to access host-level resources from a guest process ID.
* **Detection methods:** Audit logs for hypervisor crashes or unusual VMM (Virtual Machine Monitor) behavior.
## References
* Vercel Bug Bounty Announcement: hxxps[://]x[.]com/rauchg/status/210640202480402065
* Researcher Social Media (Paulos Yibelo): hxxps[://]x[.]com/PaulosYibelo/status/2106378929158135903
* Firecracker MicroVM Project: hxxps[://]firecracker-microvm[.]github[.]io/