bhyve privileged guest escape via fwctl
CVE-2023-3494
What is CVE-2023-3494?
A vulnerability in the fwctl driver of FreeBSD can lead to a buffer overflow when a bhyve guest accesses specific x86 I/O ports. This flaw allows for the potential execution of malicious code on the host system, specifically within the bhyve userspace process, which generally operates with root privileges. Although mitigated by certain capabilities offered through the Capsicum sandbox, the risk posed by executing privileged software in a guest VM highlights the need for timely updates and proper configuration.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FreeBSD 13.2-RELEASE < 13.2-RELEASE-p2
FreeBSD 13.1-RELEASE < 13.1-RELEASE-p9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
