#VU46742 Security restrictions bypass in FreeBSD - CVE-2020-24718
Published: September 16, 2020
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists in bhyve(8) hypervisor due to application does not properly impose security restrictions. A remote root user on the host within jailed environment can run a specially crafted program to execute arbitrary code on systems that rely on bhyve(8) in jail for security domain separation.