Google will begin offering rewards for identifying vulnerabilities in the KVM hypervisor.

Google has launched the kvmCTF initiative, where security researchers can earn monetary rewards for discovering vulnerabilities in the KVM (Kernel-based Virtual Machine) hypervisor. Google's interest in KVM stems from its use in Google Cloud services, as well as in Android and ChromeOS platforms (CrosVM is based on KVM). To receive a reward, an attacker must demonstrate a breach of a specially prepared CTF (Capture the Flag) environment running a fresh Linux kernel, with access to a virtual machine provided on request. The attacker is challenged to exploit a vulnerability in the subsystem KVM in the Linux kernel that supports the host system in this environment.

A reward of $250,000 is offered for discovering a previously unknown vulnerability that allows breaking out of the virtual machine, while $100,000 is designated for vulnerabilities that enable writes to arbitrary memory areas. A payment of $50,000 is set for vulnerabilities leading to reading from arbitrary memory or writing to adjacent memory areas, $20,000 for a DoS vulnerability, and $10,000 for reading from adjacent memory. The reward for writing or reading from arbitrary memory can be claimed by modifying or obtaining the value of a specific memory address, and for adjacent memory, it is based on errors recognized by the KASAN (Kernel address sanitizer) debug tool, such as buffer overflow or accessing already freed memory. The DoS vulnerability reward is awarded upon detecting a null pointer dereference (null-ptr-deref in KASAN).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster