From virtio-snd 0-day to hypervisor escape: exploiting QEMU with an uncontrolled heap overflow
osec.io | research | #zero-day | #exploit | #heap-overflow | #qemu | #glibc | #virtio | #hypervisor-escape
Summary
OtterSec turns an uncontrolled heap overflow in QEMU's virtio-snd 0-day into a reliable guest-to-host escape using new glibc allocator behavior and QEMU-specific heap sprays.
- Published
- Collected
Skip to content