Google · AMD · Intel · Ars Technica
Google pays $250K for Linux vulnerability allowing guest VM escapes
Compiled by KHAO Editorial — aggregated from 1 source + 3 references discovered via search. See llms.txt for citation guidance.
◌ Single Source
A Linux vulnerability that allows untrusted virtual machines to gain root access to host machines is one of two high-severity flaws to surface this week in the open source operating system.
Key facts
- Tracked as CVE-2026-43499, it lurked in the OS for 15 years
- The vulnerability, which Nebula has named GhostLock, has a severity rating of 7.8 out of 10
- Google has awarded $250,000 for the reporting of the vulnerability
- Like the $250,000 bounty paid for Januscript, it was awarded through Google’s kernelCTF bug-bounty program
Summary
The vulnerability resides in KVM, which is, in essence, a virtual machine app included in the kernel of many Linux distributions. The vulnerability affects KVM running on both AMD and Intel processors. “With guest-side actions alone, an attacker can compromise the host that runs their VM,” Hyunwoo Kim, the researcher who discovered the flaw, wrote. Kim has named the vulnerability Januscape.