3 ms·
Anyone know if "-cpu ${CPU},vmx=off,svm=off" in QEMU is a safe workaround for this? (To disable nested virtualization on a per-VM basis. Only against exploitat
by eqvinox 2mo ago
Anyone know if "-cpu ${CPU},vmx=off,svm=off" in QEMU is a safe workaround for this?
(To disable nested virtualization on a per-VM basis. Only against exploitation from within that specific VM, obviously does nothing against users with access to /dev/kvm on the host.)
[That did work around Januscape: https://news.ycombinator.com/item?id=48815819 https://news.ycombinator.com/item?id=48815819]
- esjeon 2mo agoThis one(Zapscape) exploits the same module(shadow MMU) as Januscape, so it does workaround the issue. AFAIK the only code paths that activates shadow MMU are (1) lack of hardware EPT/NPT support (2) nested virtualization. Hiding `vmx`/`svm` prevents access to the second code path.