VYPR
Medium severity6.3NVD Advisory· Published Feb 15, 2024· Updated Jun 17, 2026

CVE-2024-25940

CVE-2024-25940

Description

bhyveload -h may be used to grant loader access to the directory tree on the host. Affected versions of bhyveload(8) do not make any attempt to restrict loader's access to , allowing the loader to read any file the host user has access to. In the bhyveload(8) model, the host supplies a userboot.so to boot with, but the loader scripts generally come from the guest image. A maliciously crafted script could be used to exfiltrate sensitive data from the host accessible to the user running bhyhveload(8), which is often the system root.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

19
  • FreeBSD/FreeBSD18 versions
    cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*+ 17 more
    • cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*range: <13.2
    • cpe:2.3:o:freebsd:freebsd:13.2:p1:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.2:p2:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.2:p3:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.2:p4:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.2:p5:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.2:p6:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.2:p7:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.2:p8:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.2:p9:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:beta5:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p1:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p2:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p3:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p4:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:rc3:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:rc4-p1:*:*:*:*:*:*
    • (no CPE)range: 14.0-RELEASE

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.