CVE-2024-25940: Freebsd
Medium severity, CVSS 6.3. EPSS: 0.5% chance of exploitation in the next 30 days.
`bhyveload -h <host-path>` may be used to grant loader access to the <host-path> directory tree on the host. Affected versions of bhyveload(8) do not make any attempt to restrict loader's access to <host-path>, allowing the loader to read any file the host user has access to. In the bhyveload(8) model, the host supplies a userboot.so to boot with, but the loader scripts generally come from the guest image. A maliciously crafted script could be used to exfiltrate sensitive data from the host accessible to the user running bhyhveload(8), which is often the system root.
Affected products
- Freebsd Freebsd: before 13.2 (fixed in 13.2); from 13.3, before 14.0 (fixed in 14.0); version 13.2 only; version 14.0 only
Published 2024-02-15. Last modified 2026-06-17.