VMware bhyve Vulnerability Could Lead to Root Execution on Host
CVE-2024-43110

8.8HIGH

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
5 September 2024

What is CVE-2024-43110?

The ctl_request_sense function within FreeBSD's bhyve virtualization technology has a vulnerability that may inadvertently expose up to three bytes of the kernel heap to userspace environments. This exposure presents a potential risk for malicious software operating in a guest virtual machine, particularly those leveraging virtio_scsi, as it enables the execution of arbitrary code on the host. While the bhyve virtualization process operates under the constraints of a Capsicum sandbox, which limits the capabilities available to it, a malicious iSCSI initiator could exploit this vulnerability to achieve remote code execution on the iSCSI target host, raising significant security concerns.

Affected Version(s)

FreeBSD 14.1-RELEASE

FreeBSD 14.0-RELEASE

FreeBSD 13.3-RELEASE

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Synacktiv
The FreeBSD Foundation
The Alpha-Omega Project
.