<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/security-researcher-claims-to-they-found-kvm-guest-host-escape-flaw-1gpdgqots" -->

---
title: Security researcher claims to they found KVM guest-host...
description: A security researcher named Paulos Yibelo claims to have found a full guest-to-host VM escape zero-day in Linux KVM, the hypervisor underlying most major...
canonical: https://daily.dev/posts/security-researcher-claims-to-they-found-kvm-guest-host-escape-flaw-1gpdgqots
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Security researcher claims to they found KVM guest-host escape flaw | daily.dev
og:description: A security researcher named Paulos Yibelo claims to have found a full guest-to-host VM escape zero-day in Linux KVM, the hypervisor underlying most major...
og:url: https://daily.dev/posts/security-researcher-claims-to-they-found-kvm-guest-host-escape-flaw-1gpdgqots
og:image: https://api.daily.dev/og/posts/1gpdGqOtS.png
og:image:alt: Security researcher claims to they found KVM guest-host escape flaw
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Security researcher claims to they found KVM guest-host escape flaw

**[The Register](https://daily.dev/sources/theregister)** · 3 min read · 0 upvotes · 0 comments

## Summary

A security researcher named Paulos Yibelo claims to have found a full guest-to-host VM escape zero-day in Linux KVM, the hypervisor underlying most major clouds, discovered via Vercel's bug bounty program for its Sandbox product (built on AWS's Firecracker MicroVMs). Vercel CEO Guillermo Rauch confirmed the KVM 0-day on X, but no technical details, CVE, or mailing-list discussion have surfaced yet. Because KVM powers AWS, Google Cloud, Nutanix, HPE, and Proxmox, a guest-host escape would be catastrophic if exploited before a responsible disclosure and patch. This follows an earlier KVM bug, the so-called Januscape flaw, found earlier in the year.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.theregister.com/offbeat/2026/10/06/security-researcher-claims-to-they-found-kvm-guest-host-escape-flaw/5301267>

## Questions this post answers

### What is the KVM guest-to-host VM escape zero-day that was recently found?

A security researcher, Paulos Yibelo, claims to have discovered a full guest-to-host VM escape zero-day in Linux KVM, the kernel-level hypervisor used by AWS, Google Cloud, Nutanix, HPE, and Proxmox. It was found through Vercel's Sandbox bug bounty program, which uses AWS's Firecracker MicroVMs built on KVM. Vercel's CEO confirmed the KVM 0-day, but no patch, CVE, or technical writeup has been published yet.

_daily.dev surfaces infrastructure security disclosures like this KVM escape as patches and details emerge._

### Why are guest-to-host VM escapes considered especially dangerous for cloud infrastructure?

A guest-to-host escape lets whoever controls a guest VM take over the entire physical server and potentially other guest VMs running on it, making it the worst-case scenario for multi-tenant virtualization. This matters enormously for KVM specifically because it underpins major public clouds and enterprise virtualization products, so a leaked exploit before a fix ships could enable widespread attacks across cloud providers.

_teams running multi-tenant workloads can track hypervisor escape risks and patch guidance via daily.dev._

### Can a KVM security patch be applied without taking servers offline?

Yes, it is possible to hot-patch KVM and to live-migrate running VMs off a vulnerable host onto machines already running a patched version of Linux, avoiding downtime during remediation. Whether this approach works smoothly for the newly reported guest-host escape zero-day remains to be seen once a fix is actually released.

_ops teams planning zero-downtime hypervisor patching can follow KVM fix details on daily.dev._

## Similar posts on daily.dev

- [New Linux kernel flaw allows VM escape on Intel, AMD devices](https://daily.dev/posts/new-linux-kernel-flaw-allows-vm-escape-on-intel-amd-devices-pgteqqq1i) · BleepingComputer · 2 upvotes · 0 comments
- [16-year-old KVM flaw allows attackers to escape VMs and take over Linux servers](https://daily.dev/posts/16-year-old-kvm-flaw-allows-attackers-to-escape-vms-and-take-over-linux-servers-gx1scspvh) · CSO Online · 0 upvotes · 0 comments
- [Google pays $250K for Linux vulnerability allowing guest VM escapes](https://daily.dev/posts/google-pays-250k-for-linux-vulnerability-allowing-guest-vm-escapes-dp9gdnmga) · Ars Technica · 2 upvotes · 0 comments

---

Tags: [#vercel](https://daily.dev/tags/vercel)

[View this post on daily.dev](https://daily.dev/posts/security-researcher-claims-to-they-found-kvm-guest-host-escape-flaw-1gpdgqots)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Security researcher claims to they found KVM guest-host escape flaw","url":"https://daily.dev/posts/security-researcher-claims-to-they-found-kvm-guest-host-escape-flaw-1gpdgqots","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/security-researcher-claims-to-they-found-kvm-guest-host-escape-flaw-1gpdgqots"},"datePublished":"2026-10-06T02:09:13.510Z","dateModified":"2026-10-06T02:10:01.578Z","description":"A security researcher named Paulos Yibelo claims to have found a full guest-to-host VM escape zero-day in Linux KVM, the hypervisor underlying most major...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/716da7514ae6f6a0adf03fa8e0c9e3e6?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/716da7514ae6f6a0adf03fa8e0c9e3e6?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Register","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Register","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/66aa2113fdad463992ffcbf0e8963fda","url":"https://daily.dev/sources/theregister"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/security-researcher-claims-to-they-found-kvm-guest-host-escape-flaw-1gpdgqots","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"vercel","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Register","item":"https://daily.dev/sources/theregister"},{"@type":"ListItem","position":3,"name":"Security researcher claims to they found KVM guest-host escape flaw"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/security-researcher-claims-to-they-found-kvm-guest-host-escape-flaw-1gpdgqots#faq","mainEntity":[{"@type":"Question","name":"What is the KVM guest-to-host VM escape zero-day that was recently found?","acceptedAnswer":{"@type":"Answer","text":"A security researcher, Paulos Yibelo, claims to have discovered a full guest-to-host VM escape zero-day in Linux KVM, the kernel-level hypervisor used by AWS, Google Cloud, Nutanix, HPE, and Proxmox. It was found through Vercel's Sandbox bug bounty program, which uses AWS's Firecracker MicroVMs built on KVM. Vercel's CEO confirmed the KVM 0-day, but no patch, CVE, or technical writeup has been published yet. daily.dev surfaces infrastructure security disclosures like this KVM escape as patches and details emerge."}},{"@type":"Question","name":"Why are guest-to-host VM escapes considered especially dangerous for cloud infrastructure?","acceptedAnswer":{"@type":"Answer","text":"A guest-to-host escape lets whoever controls a guest VM take over the entire physical server and potentially other guest VMs running on it, making it the worst-case scenario for multi-tenant virtualization. This matters enormously for KVM specifically because it underpins major public clouds and enterprise virtualization products, so a leaked exploit before a fix ships could enable widespread attacks across cloud providers. teams running multi-tenant workloads can track hypervisor escape risks and patch guidance via daily.dev."}},{"@type":"Question","name":"Can a KVM security patch be applied without taking servers offline?","acceptedAnswer":{"@type":"Answer","text":"Yes, it is possible to hot-patch KVM and to live-migrate running VMs off a vulnerable host onto machines already running a patched version of Linux, avoiding downtime during remediation. Whether this approach works smoothly for the newly reported guest-host escape zero-day remains to be seen once a fix is actually released. ops teams planning zero-downtime hypervisor patching can follow KVM fix details on daily.dev."}}]}
```

