VMware bhyve Vulnerability Could Lead to Root Execution on Host
CVE-2024-43110
What is CVE-2024-43110?
The ctl_request_sense function within FreeBSD's bhyve virtualization technology has a vulnerability that may inadvertently expose up to three bytes of the kernel heap to userspace environments. This exposure presents a potential risk for malicious software operating in a guest virtual machine, particularly those leveraging virtio_scsi, as it enables the execution of arbitrary code on the host. While the bhyve virtualization process operates under the constraints of a Capsicum sandbox, which limits the capabilities available to it, a malicious iSCSI initiator could exploit this vulnerability to achieve remote code execution on the iSCSI target host, raising significant security concerns.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FreeBSD 14.1-RELEASE
FreeBSD 14.0-RELEASE
FreeBSD 13.3-RELEASE
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
