High severity8.2NVD Advisory· Published Sep 5, 2024· Updated Jun 17, 2026
CVE-2024-32668
CVE-2024-32668
Description
An insufficient boundary validation in the USB code could lead to an out-of-bounds write on the heap, with data controlled by the caller.
A malicious, privileged software running in a guest VM can exploit the vulnerability to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
27cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*+ 25 more
- cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*range: >=13.0,<13.3
- cpe:2.3:o:freebsd:freebsd:13.3:-:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.3:p1:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.3:p2:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.3:p3:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.3:p4:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.3:p5:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.4:beta3:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:-:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:beta5:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p1:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p2:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p3:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p4:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p5:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p6:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p7:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p8:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p9:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:rc3:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:rc4-p1:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.1:-:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.1:p1:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.1:p2:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.1:p3:*:*:*:*:*:*
- (no CPE)range: 14.1-RELEASE
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.