Kernel module

QEMU and the other VMMs emulate devices in user space, but the CPU and memory virtualization runs in the KVM kernel module. That module is a different, higher-value target than the VMM: a bug there lands in the host kernel directly, bypassing the seccomp and sVirt confinement that boxes in QEMU. The surface is small but severe, and it is shared by every KVM-based VMM, QEMU, Firecracker, Cloud Hypervisor, and the rest.

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more