Skip to main content

Venom’s bite could be worse than Heartbleed’s bark

venom could pack a deadlier bite than heartbleed f3jutjz
Image Credit: Crowdstrike
According to a report released by the security firm CrowdStrike, millions of datacenters around the world could be victims of a new vulnerability that affects the software which manages floppy disk controllers on virtual machines.

Most datacenters today work by installing virtualized environments on their servers, a standard practice which allows them to save space and better optimize the way that larger and smaller companies share bandwidth between them.

Recommended Videos

The codeword for the bug, called ‘Venom’, is actually an abbreviation of the full title of the vulnerability —  the “Virtualized Environment Neglected Operations Manipulation”– which is based off which parts of the system it attacks.

A collection of virtualized machines running off one machine is what’s known as a “hypervisor”, and what makes Venom significant is its ability to use the open-source computer emulator QEMU to hijack the floppy disk controller and affect all the sandboxes under the same hypervisor umbrella.

“Millions of virtual machines are using one of these vulnerable platforms,” said CrowdStrike’s Jason Geffner, the researcher who found the bug.

Thankfully, CrowdStrike has been working closely with major datacenter providers over the past few months to get the hole patched before publicly disclosing its existence today. This approach is in stark contrast to what we saw with Heartbleed, wherein the free-for-all of patching vulnerabilities was left to whoever could jump on the pile first after the news initially broke.

So far no exploits have been detected in the wild, despite the fact that the bug has been installed in the affected systems since as early as 2004. For now, the main virtualization platforms under fire include KVM, VirtualBox, and Xen, while VMWare, Hyper-V, and Bochs hypervisors are in the clear.

With the majority of providers utilizing systems based off the latter half of this list, hopefully the threat will be reigned in before things spiral too far out of control.

Chris Stobing
Former Digital Trends Contributor
Self-proclaimed geek and nerd extraordinaire, Chris Stobing is a writer and blogger from the heart of Silicon Valley. Raised…
This Lenovo ThinkPad is almost $1,800 off today!
A press photo of the ThinkPad X1 Carbon Gen 11.

One of the best laptops for a busy computer-heavy workplace is the Lenovo ThinkPad. For years, this tried and true laptop and 2-in-1 has delivered a fast and reliable Windows experience to many a 9 to 5 go-getter. Processor speed and power evolve year over year, and new features are added to these laptops all the time. This also means you’ll be able to find discounts on older machines, which is precisely what we came across while scouring through Lenovo ThinkPad deals:

Right now, as part of Lenovo’s doorbuster sale, you’ll save $1,800 on the purchase of a brand-new Lenovo ThinkPad X1 Carbon Gen 11 when you order through Lenovo.

Read more
Runway brings precise camera controls to AI videos
Gen-3 alpha advanced camera controls

Content creators will have more control over the look and feel of their AI-generated videos thanks to a new feature set coming to Runway's Gen-3 Alpha model.

Advanced Camera Control is rolling out on Gen-3 Alpha Turbo starting today, the company announced via a post on X (formerly Twitter).

Read more
Score the Dell XPS 15 for less than $1,000 during this sale
Dell XPS 15 9520 front view showing display and keyboard deck.

If you’ve been looking for laptop deals but feel disappointed with the results of your research, we know the pain. Searching for a new PC can take months, especially if you’ve got the time and energy to vet through numerous brands and models. Fortunately, there are a few tried and true PC names, one of which happens to be Dell. We see Dell laptop deals pretty regularly, but this one stopped us in our tracks:

Right now, when you order the Dell XPS 15 Laptop through the manufacturer, you’ll save $300. At full price, this model sells for $1,300.

Read more