A critical 16-year-old vulnerability in the Linux KVM subsystem allows guest virtual machines to corrupt host memory, potentially impacting major cloud providers like Amazon AWS and Google GCP.
Key Points
- The Januscape vulnerability enables guest-to-host isolation breakouts within the Linux Kernel Virtual Machine (KVM) environment.
- KVM is a foundational technology for major cloud platforms, including Amazon AWS, Google GCP, and Digital Ocean.
- The flaw has existed for 16 years, spanning nearly the entire operational history of the Linux KVM subsystem.
- Patches for the vulnerability are currently available in the Linux mainline kernel for immediate deployment by hosting providers.