#VU99537 Out-of-bounds write in FreeBSD - CVE-2024-42416
Published: October 31, 2024
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a malicious guest to execute arbitrary code on the system.
The vulnerability exists due to a boundary error within the ctl_report_supported_opcodes() function. A malicious guest running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process (e.g. as root).