CVE-2016-1889: Freebsd

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of guest memory, allows local users to gain privilege via a crafted device descriptor.

Affected products

  • Freebsd Freebsd: version 10.1 only; version 10.2 only; version 10.3 only; version 11.0 only

Published 2017-02-15. Last modified 2026-06-17.