information about (), allowing to escape the guest system in KVM (qemu-kvm) and execute custom code on the host environment in the context of the Linux kernel. The vulnerability has been assigned the codename V-gHost. This issue permits the creation of conditions for a buffer overflow in the vhost-net kernel module (network backend for virtio), executed on the host environment side, from the guest system. An attack can be carried out by an adversary with privileged access in the guest system during the virtual machine migration operation.
Fix for the issue is included in the Linux kernel 5.3. As a workaround to block the vulnerability, live migration of guest systems can be prohibited or the vhost-net module can be disabled (add 'blacklist vhost-net' to /etc/modprobe.d/blacklist.conf). The issue appears starting from Linux kernel 2.6.34. The vulnerability has been resolved in and , but remains unpatched in , , and .
Source: opennet.ru
