top | item 44147410

(no title)

billywhizz | 9 months ago

is there anything good written up on this?

discuss

order

tptacek|9 months ago

I don't think so? It's not complicated. Most LPEs get you the local kernel. The KVM security model assumes an untrusted local (guest) kernel. To compromise KVM, they either need to be fundamental architectural flaws (rare) or bugs in KVM itself (also rare).