4 ms·
is there anything good written up on this?
by billywhizz 1y ago
is there anything good written up on this?
- tptacek 1y agoI don't think so? It's not complicated. Most LPEs get you the local kernel. The KVM security model assumes an untrusted local (guest) kernel. To compromise KVM, they either need to be fundamental architectural flaws (rare) or bugs in KVM itself (also rare).