Open simondeziel opened 5 months ago
The VM GPU device is not always needed and having it enabled comes with additional memory overhead and bigger attack surface. Being able to easily disable it would make it simple to pack more VMs on any given host.
The bigger attack surface is probably due to GPUs being complex beast which lead to hypervisor-escapes in the past (https://census-labs.com/media/straightouttavmware-wp.pdf).
@simondeziel is this a known security issue in QEMU 8.1?
@tomponline no, this is just to highlight that vGPU comes with additional attack surface and memory usage that'd be nice to make optional.
The VM GPU device is not always needed and having it enabled comes with additional memory overhead and bigger attack surface. Being able to easily disable it would make it simple to pack more VMs on any given host.
The bigger attack surface is probably due to GPUs being complex beast which lead to hypervisor-escapes in the past (https://census-labs.com/media/straightouttavmware-wp.pdf).