VMBus is the transport underneath every synthetic device: a set of channels backed by shared-memory ring buffers that carry packets between the guest and the parent partition. The host-side VMBus code (in the kernel and the worker process) parses channel setup, ring indices, and packet headers. Flaws there corrupt host state before any higher-level device handler runs, so VMBus is a transport-level escape surface shared by all synthetic devices.
VMBus escape surface:
- Ring-buffer index and packet-header handling
- Channel offer, open, and GPADL (memory-region) setup
Exploitation notes#
- Because VMBus underlies all synthetic devices, a transport bug is broadly reachable from any guest that uses them.
- Depending on where the flaw is, it lands in the host kernel or the worker process; see Synthetic devices.
- Ring-buffer index handling is a classic corruption point in shared-ring transports.