bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.
2020-09-25T04:23:04.683
2024-11-21T05:15:57.703
Modified
CVSSv3.1: 8.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | freebsd | freebsd | ≤ 11.2 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.3 | Yes |
Operating System | freebsd | freebsd | 11.4 | Yes |
Operating System | freebsd | freebsd | 11.4 | Yes |
Operating System | freebsd | freebsd | 11.4 | Yes |
Operating System | freebsd | freebsd | 11.4 | Yes |
Operating System | freebsd | freebsd | 11.4 | Yes |
Operating System | freebsd | freebsd | 11.4 | Yes |
Operating System | freebsd | freebsd | 11.4 | Yes |
Operating System | freebsd | freebsd | 12.0 | Yes |
Operating System | freebsd | freebsd | 12.0 | Yes |
Operating System | freebsd | freebsd | 12.0 | Yes |
Operating System | freebsd | freebsd | 12.0 | Yes |
Operating System | freebsd | freebsd | 12.0 | Yes |
Operating System | freebsd | freebsd | 12.0 | Yes |
Operating System | freebsd | freebsd | 12.0 | Yes |
Operating System | freebsd | freebsd | 12.0 | Yes |
Operating System | freebsd | freebsd | 12.0 | Yes |
Operating System | freebsd | freebsd | 12.0 | Yes |
Operating System | freebsd | freebsd | 12.0 | Yes |
Operating System | freebsd | freebsd | 12.0 | Yes |
Operating System | freebsd | freebsd | 12.0 | Yes |
Operating System | freebsd | freebsd | 12.1 | Yes |
Operating System | freebsd | freebsd | 12.1 | Yes |
Operating System | freebsd | freebsd | 12.1 | Yes |
Operating System | freebsd | freebsd | 12.1 | Yes |
Operating System | freebsd | freebsd | 12.1 | Yes |
Operating System | freebsd | freebsd | 12.1 | Yes |
Operating System | freebsd | freebsd | 12.1 | Yes |
Operating System | freebsd | freebsd | 12.1 | Yes |
Operating System | freebsd | freebsd | 12.1 | Yes |
Operating System | freebsd | freebsd | 12.1 | Yes |
Operating System | omniosce | omnios | ≤ r151034 | Yes |
Operating System | openindiana | openindiana | ≤ hipster_2020.04 | Yes |
Application | netapp | clustered_data_ontap | - | Yes |