Vercel confirms KVM zero
Vercel has confirmed a KVM zero-day reported through its Sandbox bug bounty program, with researcher Paulos Yibelo claiming it enables a virtual machine to escape and gain root access on its host. Vercel Sandbox runs Firecracker microVMs on KVM, but the vulnerability’s technical details and affected versions have not been made public. There is not yet enough information to determine which KVM deployments are affected or what fix administrators should apply. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
