Vulnerability in vhost-net allowing bypass of isolation in QEMU-KVM based systems
Information has been revealed about a vulnerability (CVE-2019-14835) that allows an escape from the guest system in KVM (qemu-kvm) and the execution of arbitrary code in the host environment context within the Linux kernel. The vulnerability has been given the codename V-gHost. The issue allows the guest system to create conditions for a buffer overflow in the vhost-net kernel module (network backend for virtio), which is executed in the host environment. An attack can be […]
