QEMU and the other VMMs emulate devices in user space, but the CPU and memory virtualization runs in the KVM kernel module. That module is a different, higher-value target than the VMM: a bug there lands in the host kernel directly, bypassing the seccomp and sVirt confinement that boxes in QEMU. The surface is small but severe, and it is shared by every KVM-based VMM, QEMU, Firecracker, Cloud Hypervisor, and the rest.
Subtopics#
- Kernel module escape: host kernel code execution through the KVM module.
- Nested virtualization: escapes through the nested VMX and SVM state machine.