CVE-2020-24718: Freebsd
High severity, CVSS 8.2. EPSS: 0.6% chance of exploitation in the next 30 days.
bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.
Affected products
- Freebsd Freebsd: up to and including 11.2; version 11.3 only; version 11.4 only; version 12.0 only; version 12.1 only
- Netapp Clustered Data Ontap: affected versions not specified
- Omniosce Omnios: up to and including r151034
- Openindiana Openindiana: up to and including hipster_2020.04
Published 2020-09-25. Last modified 2026-06-17.