bhyve privileged guest escape via fwctl
CVE-2023-3494
8.8HIGH
What is CVE-2023-3494?
A vulnerability in the fwctl driver of FreeBSD can lead to a buffer overflow when a bhyve guest accesses specific x86 I/O ports. This flaw allows for the potential execution of malicious code on the host system, specifically within the bhyve userspace process, which generally operates with root privileges. Although mitigated by certain capabilities offered through the Capsicum sandbox, the risk posed by executing privileged software in a guest VM highlights the need for timely updates and proper configuration.
Affected Version(s)
FreeBSD 13.2-RELEASE < 13.2-RELEASE-p2
FreeBSD 13.1-RELEASE < 13.1-RELEASE-p9