#VU99514 Out-of-bounds read in FreeBSD - CVE-2024-41721
Published: October 30, 2024
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a malicious guest to compromise the affected system.
The vulnerability exists due to a boundary condition in bhyve(8) when emulating device on a USB controller via XHCI emulation. A malicious guest can trigger an out-of-bounds read and crash the hypervisor or execute arbitrary code.
Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process.