Full Report
Firecracker MicroVMs, which started at AWS, seem to be the problem
Analysis Summary
# Vulnerability: Potential KVM/Firecracker Guest-to-Host Escape
## CVE Details
- **CVE ID**: [Pending / Not yet assigned]
- **CVSS Score**: Not yet rated (Estimated Critical)
- **CWE**: Likely CWE-829 (Inclusion of Functionality from Untrusted Control Sphere) or CWE-20 (Improper Input Validation) leading to VM Escape.
## Affected Systems
- **Products**: Linux KVM (Kernel-based Virtual Machine), Firecracker MicroVM, Vercel Sandbox.
- **Versions**: "Industry standard" KVM versions; specific version range currently undisclosed.
- **Configurations**: Systems utilizing KVM for hardware virtualization, specifically lightweight MicroVM implementations like Firecracker used in serverless or AI agent sandboxing environments.
## Vulnerability Description
Based on preliminary reports from security researcher Paulos Yibelo and Vercel CEO Guillermo Rauch, this is a **zero-day guest-to-host escape** vulnerability. The flaw reportedly allows an attacker with root access within a guest Virtual Machine (VM) to break out of the isolation layer and execute code as root on the host operating system. While the flaw was demonstrated on Vercel’s Firecracker-based infrastructure, the vulnerability is stated to reside within the underlying KVM hypervisor itself.
## Exploitation
- **Status**: PoC confirmed by researcher/vendor; not currently reported as exploited in the wild.
- **Complexity**: High (Requires specialized knowledge of hypervisor internals).
- **Attack Vector**: Local (Attacker must already have execution rights/root access within a guest VM).
## Impact
- **Confidentiality**: Total (Host-level access allows reading all data on the physical server).
- **Integrity**: Total (Host-level access allows modification of the host kernel and other guest VMs).
- **Availability**: Total (Attacker can shut down the host or crash the hypervisor).
## Remediation
### Patches
- **Status**: No public patch is currently available. The vulnerability is undergoing a responsible disclosure process.
- **Expected Action**: Cloud providers and enterprise virtualization vendors (AWS, Google Cloud, Nutanix, Proxmox) are expected to deploy hot-patches or kernel updates once the disclosure period concludes.
### Workarounds
- **Strict Isolation**: Until a patch is released, avoid running untrusted code from high-risk sources within KVM-based environments where multi-tenancy is a concern.
- **Enhanced Monitoring**: Implement rigorous monitoring of host-side syscalls and unexpected process behavior originating from hypervisor threads.
## Detection
- **Indicators of Compromise**: Unexpected root-level processes on the host machine originating from the `firecracker` or `kvm` process space; unauthorized access to host `/proc` or `/sys` filesystems.
- **Detection Methods**: Use of eBPF-based security tools (like Tetragon or Falco) to monitor for anomalous escapes from the VM boundary.
## References
- **Researcher Social Media**: hxxps[://]x[.]com/PaulosYibelo/status/2106378929158135903
- **Vendor Acknowledgment**: hxxps[://]x[.]com/rauchg/status/210640202480402065
- **Technology Context**: hxxps[://]aws[.]amazon[.]com/blogs/aws/firecracker-lightweight-virtualization-for-serverless-computing/