Public QEMU escapes recur across its device models. The VENOM class exploited the legacy floppy disk controller, reachable even when the floppy appears absent. virtio, the e1000 and rtl8139 NICs, and the USB and SCSI controllers have all produced host code execution in the QEMU process. Rarer, more powerful bugs have been found in the KVM kernel module itself, which yield host kernel code directly.
Recurring KVM/QEMU escape surfaces:
- The floppy disk controller (VENOM)
- virtio devices (net, block, gpu)
- Legacy NICs: e1000, rtl8139
- USB and SCSI controllers
Exploitation notes#
- QEMU-level escapes are bounded by host confinement (seccomp, sVirt, non-root QEMU); a hardened host contains them to the QEMU sandbox, so enumerate the confinement before assuming full host access.
- Bugs in the KVM kernel module bypass that confinement entirely by landing in the host kernel, but are far rarer.
- The surface map is in Guest to host escape.