PT-2024-8610 · Bhyve+1 · Bhyve+1

Synacktiv

·

Published

2024-09-04

·

Updated

2024-09-09

·

CVE-2024-42416

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions bhyve (affected versions not specified)
Description The issue is related to the ctl report supported opcodes function, which did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory. This could be exploited by malicious software running in a guest VM that exposes virtio scsi to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process. A malicious iSCSI initiator could achieve remote code execution on the iSCSI target host.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-10179
CVE-2024-42416
FREEBSD-SA-24_11

Affected Products

Freebsd
Bhyve