bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HFreebsd
OSFreebsd11.311.412.012.1≤ 11.2Netapp Clustered Data Ontap
APPNetappall versionsOmniosce Omnios
OSOmniosce≤ r151034Openindiana
OSOpenindiana≤ hipster_2020.04
Related vulnerabilities
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-sup...
The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character outp...
FreeBSD UMTX_SHM_DESTROY: use-after-free umożliwiający RCE lub ucieczkę z sandboxa
Apache HTTP Server – ujawnienie danych, SSRF lub wykonanie skryptu przez nagłówki backendu