CVE-2024-41928: Freebsd
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process.
Affected products
- Freebsd Freebsd: from 14.1-RELEASE, before p4 (fixed in p4); from 14.0-RELEASE, before p10 (fixed in p10); from 14.1, before 14.1_p4 (fixed in 14.1_p4); from 14.0, before 14.0_p10 (fixed in 14.0_p10)
Published 2024-09-05. Last modified 2026-06-17.