Description
Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process.
Problem types
CWE-1285 Improper Validation of Specified Index, Position, or Offset in Input
Product status
14.1-RELEASE (release) before p4
14.0-RELEASE (release) before p10
Credits
Synacktiv
The FreeBSD Foundation
The Alpha-Omega Project
References
security.netapp.com/advisory/ntap-20240920-0009/
security.freebsd.org/advisories/FreeBSD-SA-24:10.bhyve.asc