← Back

CVE-2020-24718

nvd nist
Published: Sep 25, 2020Modified: Jun 17, 2026

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Exploitability: 1.5 / Impact: 6.0
Source: NVD

Description

bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.

Affected (49)

Products: Freebsd: Freebsd · Omniosce: Omnios · Openindiana: Openindiana · +1 more
Show all products
1 product
Freebsd
1 product
Omnios
1 product
Openindiana
1 product
Clustered Data Ontap
Configuration A
46 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Up to 11.2
Version 11.3
Version 11.3 p10
Version 11.3 p11
Version 11.3 p12
Version 11.3 p13
Version 11.3 p1
Version 11.3 p2
Version 11.3 p3
Version 11.3 p4
Version 11.3 p5
Version 11.3 p6
Version 11.3 p7
Version 11.3 p8
Version 11.3 p9
Version 11.3 rc3
Version 11.4
Version 11.4 beta1
Version 11.4 p1
Version 11.4 p2
Version 11.4 p3
Version 11.4 rc1
Version 11.4 rc2
Version 12.0
Version 12.0 p10
Version 12.0 p11
Version 12.0 p12
Version 12.0 p1
Version 12.0 p2
Version 12.0 p3
Version 12.0 p4
Version 12.0 p5
Version 12.0 p6
Version 12.0 p7
Version 12.0 p8
Version 12.0 p9
Version 12.1
Version 12.1 p1
Version 12.1 p2
Version 12.1 p3
Version 12.1 p4
Version 12.1 p5
Version 12.1 p6
Version 12.1 p7
Version 12.1 p8
Version 12.1 p9
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to r151034
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to hipster_2020.04
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

Timeline

No history available yet.