#virtualization

46 posts · Last used 2d

Zapscape (CVE-2026-64561) is another reminder that the hypervisor boundary is only as strong as the code implementing it. The vulnerability is a guest-to-host escape in Linux KVM's x86 Shadow MMU. The root cause is a stale-root validation ordering bug that allows the page fault handler to continue using an invalidated shadow MMU root after quota reclaim, ultimately leading to a use-after-free primitive. Public research demonstrates a complete guest-to-host escape chain, although exploitation requires privileged code execution inside an L1 guest and nested virtualization exposure. I put together a deep technical analysis covering the Shadow MMU internals, nested virtualization, exploitation stages, cross-cache reallocation, KASLR bypass, AMD vs. Intel trigger conditions, the upstream fix, and why simply moving a stale-root check eliminates the entire exploitation chain. Interested to hear how others assess the practical risk for multi-tenant KVM deployments where nested virtualization is enabled. https://thecybersecguru.com/news/zapscape-cve-2026-64561-kvm-guest-host-escape/ #Linux #KVM #Virtualization #KernelSecurity #CloudSecurity #CVE202664561
1
0
0
0
#PegaProx just got released in v1.0 and is out of beta now! PegaProx for #Proxmox VE and #XCPng clusters made a huge step and is finally out of beta! The first stable release also comes around with companies providing enterprise support. If you need SLA-backed help running PegaProx in production (or training sessions) you can now find a support partner at: Enterprise Support & Sponsors: https://pegaprox.com/sponsors.html Release: https://github.com/PegaProx/project-pegaprox/releases/tag/v1.0 Website: https://pegaprox.com #homelab #virtualization #opensource #community #python #virtualization #enterprise #business #support
0
3
0
0
More AI news from AMD, re-use of the better parts of their Strix Halo yield for industrial use cases. "Physical AI" aka robotics and edge use cases. Buzzword galore! 😆 Still remember when "edge" was the new buzzword Pepperidge Farm Remembers https://www.servethehome.com/amds-physical-ai-plans-come-into-focus-as-company-launches-ryzen-embedded-ai-x100/ Something I do find interesting is the claim of hard real-time assurances whilst virtualized with Xen. Technically a guaranteed deadline of 2 years is hard real-time too, just as MS-DOS is an amazing real-time OS, but I'm sure that's not what they're talking about... Any one got more info on the Xen claim? Haven't heard so much about them these days... #amd #strixhalo #ai #EmbedddedSystems #PhysicalAI #edgecomputing #robotics #xen #virtualization #realtime
0
0
1
0
🚨 Critical VMware Advisory Broadcom has patched multiple critical VMware vulnerabilities affecting vCenter Server and ESXi, including an authentication bypass (CVSS 9.8), directory traversal leading to RCE (CVSS 9.8), and a VM escape via VMXNET3 (CVSS 9.3). Organizations should prioritize patching vCenter and ESXi infrastructure as soon as possible. Technical breakdown, affected versions, and mitigation: https://thecybersecguru.com/news/critical-vmware-vcenter-auth-bypass-rce-vm-escape-vulnerabilities/ #InfoSec #CyberSecurity #VMware #vCenter #ESXi #Virtualization #RCE #ThreatIntel #BlueTeam #SysAdmin #CVE
1
0
0
0