Vercel Paid $50k for a KVM Escape That Has No CVE and No Patch

On October 3 security researcher Paulos Yibelo posted five words that every operator of a Linux virtualisation fleet reads differently from everyone else: “Full VM escape zeroday (guest>host root in industry standard hypervisors)! More soon.” Ninety minutes later Vercel’s chief executive Guillermo Rauch quoted the post and confirmed it: “We’ve confirmed a KVM 0day through our Vercel Sandbox bounty…

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论