By Simon Sharwood
Publication Date: 2026-10-06 02:06:00
Linux KVM, the hypervisor favoured by hyperscale clouds, apparently has a full VM escape bug.
That nasty news came from security researcher Paulos Yibelo, who on X shared a screenshot of a bug bounty award he won for discovering what he described as “Full VM escape zeroday (guest>host root in industry standard hypervisors)!”
The bug bounty Yibelo participated in is run by Vercel, a company that provides MicroVMs as sandboxes for AI agents to work inside. The company’s Sandbox uses Firecracker MicroVMs, a technology created by AWS, which relies on Linux KVM – the kernel level hypervisor in Linux.
Vercel CEO Guillermo Rauch named KVM as the hypervisor identified by Yibelo.
“We’ve confirmed a KVM 0day through our Vercel Sandbox bounty program. Affecting the industry’s gold standard solution for Linux virtualization,” he wrote.
And that’s all the info that has made it into the public view at this time. The Register can find no chat on relevant mailing lists. We have asked Rauch and Yibelo for additional details.
Hopefully, we don’t hear from either of them for days or weeks, for two reasons.
One is that guest-host escapes are the nightmare virtualization scenario because they mean whoever runs a guest VM…



