Each KVM guest is served by a QEMU process on the host that emulates its devices in user space. Those device models parse guest-controlled input, so a memory-corruption flaw in one runs code in the host QEMU process. The surface splits by device, and which models are reachable depends on the guest's configured hardware.
Code execution lands in the host QEMU process, whose reach depends on the host's confinement (seccomp, sVirt, non-root QEMU). A flaw in the KVM kernel module beneath QEMU bypasses that confinement entirely. The same QEMU code backs Proxmox and Nutanix AHV.
Subtopics#
- virtio devices: the virtqueue-based paravirtualized devices.
- Network adapters: the e1000 and rtl8139 models.
- USB controllers: UHCI, EHCI, and XHCI emulation.
- Block and SCSI: AHCI, IDE, and emulated SCSI.
- Floppy controller: the VENOM class.
- Audio devices: AC97, Intel HDA, and ES1370.