Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Every LLM bug in the Linux kernel (warehouse rave edit).

    (This comment is a reference to https://youtu.be/v1Mfirg2-Z8

  • Another serious critical vulnerability that almost no-one cares about, when they should.
    by rvz
  • Oh yay another one lol. This one seems much more general than the prior one that needed nested page tables.

    Patch Thursday for cloud VM ppl lol

  • > Q: Do you think KVM vulnerabilities will keep appearing?

    > A: Yes. I recommend establishing a sustainable patching process for host hypervisors. Winter is coming.

  • In seL4, a VMM escape, hard as that'd be, yields nothing.

    VMM handles all VM exceptions, and is just another user program. It has no higher capabilities than the VM itself.

  • Anyone know if "-cpu ${CPU},vmx=off,svm=off" in QEMU is a safe workaround for this?

    (To disable nested virtualization on a per-VM basis. Only against exploitation from within that specific VM, obviously does nothing against users with access to /dev/kvm on the host.)

    [That did work around Januscape: https://news.ycombinator.com/item?id=48815819]

Explore Birbla archives