Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Every LLM bug in the Linux kernel (warehouse rave edit).
(This comment is a reference to https://youtu.be/v1Mfirg2-Z8
by inigyou - Another serious critical vulnerability that almost no-one cares about, when they should.by rvz
- Oh yay another one lol. This one seems much more general than the prior one that needed nested page tables.
Patch Thursday for cloud VM ppl lol
by minimaltom - > Q: Do you think KVM vulnerabilities will keep appearing?
> A: Yes. I recommend establishing a sustainable patching process for host hypervisors. Winter is coming.
by voidmain - In seL4, a VMM escape, hard as that'd be, yields nothing.
VMM handles all VM exceptions, and is just another user program. It has no higher capabilities than the VM itself.
by snvzz - Anyone know if "-cpu ${CPU},vmx=off,svm=off" in QEMU is a safe workaround for this?
(To disable nested virtualization on a per-VM basis. Only against exploitation from within that specific VM, obviously does nothing against users with access to /dev/kvm on the host.)
[That did work around Januscape: https://news.ycombinator.com/item?id=48815819]
by eqvinox