What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Google’s kvmCTF program lists a $250,000 reward for a demonstrated full virtual-machine escape. That is the top reward tier—not a guaranteed payment: submissions are reviewed, the exploit must prove the claimed impact, and the tiers do not stack. The program targets zero-day vulnerabilities reachable from a guest VM in the Linux KVM subsystem.
What is Google’s kvmCTF program?
Google announced kvmCTF on June 27, 2024, as part of its Vulnerability Reward Program. It gives security researchers a hosted environment to test whether they can exploit a guest-to-host vulnerability in the Kernel-based Virtual Machine (KVM) hypervisor. Google’s launch post describes a bare-metal host running one guest VM: a participant reserves a time slot, accesses the guest, and attempts an attack against the host kernel’s KVM subsystem. A flag provides evidence of success, but Google reviews reports case by case. Google’s announcement states: “The goal of the attack must be to exploit a zero day vulnerability in the KVM subsystem of the host kernel.”
How much does Google pay for a KVM VM escape?
Google’s launch post and current program rules list these rewards by demonstrated impact. The tiers do not add together. Google’s June 27, 2024 announcement and the current kvmCTF rules publish the following amounts:
| Demonstrated impact | Listed reward | Qualification |
|---|---|---|
| Full VM escape | $250,000 | Top listed tier; exploit must demonstrate a full escape. |
| Arbitrary memory write | $100,000 | Reward is based on the demonstrated impact, not merely on obtaining a flag. |
| Arbitrary memory read | $50,000 | Reward is based on the demonstrated impact, not merely on obtaining a flag. |
| Relative memory write | $50,000 | Some relative memory-access evidence uses a KASAN-enabled host. |
| Denial of service | $20,000 | Some denial-of-service evidence uses a KASAN-enabled host. |
| Relative memory read | $10,000 | Some relative memory-access evidence uses a KASAN-enabled host. |
The rules specify what each flag demonstrates. A higher-tier flag earned using a lower-tier primitive does not by itself qualify for the higher payment, and capturing a flag alone does not guarantee a reward. The listed figures are program tiers, not evidence of how frequently researchers receive them or that every tier has been paid.
#1 Best Overall
What vulnerability is in scope?
The target is a zero-day vulnerability in KVM that a guest can reach to attack the host. Although the lab uses a long-term-support (LTS) kernel, the rules require an eligible vulnerability to be reproducible in upstream Linux mainline master. A flaw limited to a downstream backport or an older LTS tree is out of scope.
Published test environment
The current rules specify Linux LTS v6.1.74 on an Intel Xeon Gold 5222 host, with the option to select a host with CONFIG_KASAN enabled or disabled. The guest is Debian 12.5 (bookworm), running kernel v6.1.0-21 with Debian’s default configuration. These describe the program’s stated test setup; they are not universal compatibility requirements for KVM.
Explicit exclusions
- QEMU vulnerabilities.
- Attacks from the host against KVM, rather than guest-to-host attacks.
- CPU, DRAM, or other hardware-based vulnerabilities.
What counts as a full VM escape?
For kvmCTF, the central distinction is demonstrated impact: the researcher must show that a guest-side exploit crosses the virtual-machine boundary and compromises the host, rather than merely reaching a lower-level memory-access or denial-of-service result. The program rules define the evidence associated with each flag and review submissions individually, so a flag is an indicator of a result—not a substitute for proving the exploit and its claimed tier.
Free tools Windows power users keep installed
One-click scans. No signup required.
How do researchers qualify for the bounty?
Eligibility includes the vulnerability’s status, the evidence submitted, and required reporting and disclosure steps. Google’s 2024 announcement says the program focuses on zero-days and does not reward n-day exploits. Under the current rules, a zero-day at submission has no patch commit in the mainline tree and has not been disclosed. Google reserves discretion, including for cases such as an older undisclosed syzkaller report with no fix.
- Exploit the target and preserve evidence. Capture the relevant flag, archive the exploit and source, and submit an initial report with the archive’s SHA-256 hash.
- Coordinate upstream. After Google responds, report the issue to security@kernel.org within seven days and pursue attribution in the upstream patch.
- Provide details and publish. Follow the rules’ process for submitting technical details and publishing the exploit in Google’s security-research repository. Reward eligibility includes publication within 90 days of disclosure.
These steps and deadlines are drawn from the live program rules; review that page before testing or submitting because procedural requirements can change.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

