All Products
Search
Document Center

:Vulnerability announcement | Zero-day VM escape

Last Updated:Aug 11, 2026

A zero-day vulnerability in QEMU-KVM that allows a VM escape was publicly disclosed at the 8th Internet Security Conference 2020 (ISC 2020). This vulnerability allows an out-of-bounds read and write of up to 0xffffffff (4 GB) of memory beyond a specific heap, enabling a complete VM escape. Alibaba Cloud has already patched this vulnerability.

Vulnerability information

This zero-day vulnerability in QEMU-KVM was first revealed at the Tianfu Cup International Cybersecurity Contest on November 17, 2019. It was later publicly disclosed at the 8th Internet Security Conference 2020 (ISC 2020) on August 13, 2020. The vulnerability allows an out-of-bounds read and write of up to 0xffffffff (4 GB) of memory beyond a specific heap. An attacker can exploit this vulnerability to achieve a complete VM escape, execute arbitrary code on the host, and potentially cause a severe information leak. As of this announcement, QEMU has not released an official patch.

Resolution

Alibaba Cloud patched this vulnerability in December 2019. No customer action is required.

Publisher

Alibaba Cloud Computing Co., Ltd.