#VU20024 Out-of-bounds write in FreeBSD - CVE-2019-5609
Published: August 9, 2019 / Updated: July 12, 2022
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a remote authenticated user to compromise vulnerable system.
The vulnerability exists due to a boundary error within bhyve(8) hypervisor when processing TCP packets sent via the e1000 network adapters. A remote user with access to guest operating system can send specially crafted TCP packets, trigger out-of-bounds write and execute arbitrary code on the host system.