Vulnerability in vhost-net allowing bypass of isolation in QEMU-KVM based systems

Disclosed information about a vulnerability (CVE-2019-14835), allowing to escape the guest system in KVM (qemu-kvm) and execute custom code on the host environment in the context of the Linux kernel. The vulnerability has been assigned the codename V-gHost. This issue permits the creation of conditions for a buffer overflow in the vhost-net kernel module (network backend for virtio), executed on the host environment side, from the guest system. An attack can be carried out by an adversary with privileged access in the guest system during the virtual machine migration operation.

Fix for the issue enabled is included in the Linux kernel 5.3. As a workaround to block the vulnerability, live migration of guest systems can be prohibited or the vhost-net module can be disabled (add 'blacklist vhost-net' to /etc/modprobe.d/blacklist.conf). The issue appears starting from Linux kernel 2.6.34. The vulnerability has been resolved in Ubuntu and Alpine, but remains unpatched in Debian, Arch Linux, openSUSE and SUSE/openSUSE.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster