AUTO-UPDATED

This Week in Security: Escaping Linux VMs, Vulnerable Solar, Confusing AI (Again), and Confusing NPM Malware

A critical 16-year-old vulnerability in the Linux KVM subsystem allows guest virtual machines to corrupt host memory, potentially impacting major cloud providers like Amazon AWS and Google GCP.

Key Points

  • The Januscape vulnerability enables guest-to-host isolation breakouts within the Linux Kernel Virtual Machine (KVM) environment.
  • KVM is a foundational technology for major cloud platforms, including Amazon AWS, Google GCP, and Digital Ocean.
  • The flaw has existed for 16 years, spanning nearly the entire operational history of the Linux KVM subsystem.
  • Patches for the vulnerability are currently available in the Linux mainline kernel for immediate deployment by hosting providers.

Why it Matters

This vulnerability poses a significant security risk to shared hosting environments that rely on KVM to isolate untrusted guest systems from physical hardware. Because the flaw allows for memory corruption and potential cross-guest access, it represents a critical threat to the integrity of multi-tenant cloud infrastructure.
Hackaday Published by Mike Kershaw
Read original