Security Advisory

CVE-2024-41928

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-09-05 03:32:56
Last updated 2024-09-20 16:03:10
Assigner freebsd
CVSS score not scored
State PUBLISHED

Description

Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process.