CVE-2024-41928
EUVD-2024-3927905.09.2024, 04:15
Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| freebsd | freebsd | 14.1 ≤ 𝑥 < 14.1_p4 | ADP |
| freebsd | freebsd | 14.0 ≤ 𝑥 < 14.0_p10 | ADP |
Common Weakness Enumeration