Resource management error in FreeBSD - #VU20353

 

Resource management error in FreeBSD - #VU20353

Published: August 21, 2019


Vulnerability identifier: #VU20353
CSH Severity: Medium
CVSS v4: 5.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-399
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to absent handling of certain instructions in bhyve(8). A remote attacker with access to guest operating system can use the unsupported instructions to crash the bhyve hypervisor.


Affected software

FreeBSD

Remediation

Install updates from vendor's website.


External References

Related Security Bulletins