KVM 虚拟机逃逸漏洞曝光
推荐指数 61.0 NO. 013 · 2026.08.07
发布2026/08/06Score63Comments9
为什么值得看
Zapscape 是 KVM/x86 影子 MMU 中的 use-after-free 漏洞,访客机无需主机配合即可获取 root 权限。对提供嵌套虚拟化的公有云构成直接威胁,多租户隔离形同虚设。
编辑判断
这个漏洞的杀伤力在于攻击面完全在访客机侧,云厂商甚至无法通过监控主机行为来检测。嵌套虚拟化本是公有云卖点的技术债——AWS Nitro、阿里云神龙架构这些硬件虚拟化方案反而免疫,纯软件 KVM 方案需要紧急评估。
如果你在用 VMware、VirtualBox 做本地开发环境,风险相对可控;但如果是基于 KVM 的 VPS 或 CI/CD 跑在第三方云上,建议立刻确认服务商是否启用了嵌套虚拟化,以及补丁状态。Hyunwoo Kim 此前还挖过 KVM 的 L1TF 变种,这条攻击链值得持续跟踪。
社区反馈
意见分歧 9 条评论
核心争论:漏洞实际影响范围:是否仅威胁嵌套虚拟化场景,还是普遍影响所有KVM/x86部署
相关内容
Another serious critical vulnerability that almost no-one cares about, when they should.
Oh yay another one lol. This one seems much more general than the prior one that needed nested page tables. Patch Thursday for cloud VM ppl lol
Do most cloud providers have live-migration or what is the approach to make this seamless? What kind of interruption might tenants notice?