Buffer Overflow Vulnerability in bhyve Userspace Process
CVE-2024-41928
Currently unrated
What is CVE-2024-41928?
Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process.
Affected Version(s)
FreeBSD 14.1-RELEASE
FreeBSD 14.0-RELEASE
References
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Synacktiv
The FreeBSD Foundation
The Alpha-Omega Project