VYPR
High severity8.8NVD Advisory· Published Sep 5, 2024· Updated Jun 17, 2026

CVE-2024-45063

CVE-2024-45063

Description

The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished processing.

Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process. A malicious iSCSI initiator could achieve remote code execution on the iSCSI target host.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

27
  • FreeBSD/FreeBSD26 versions
    cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*+ 25 more
    • cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*range: >=13.0,<13.3
    • cpe:2.3:o:freebsd:freebsd:13.3:-:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.3:p1:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.3:p2:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.3:p3:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.3:p4:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.3:p5:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.4:beta3:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:-:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:beta5:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p1:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p2:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p3:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p4:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p5:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p6:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p7:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p8:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p9:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:rc3:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:rc4-p1:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.1:-:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.1:p1:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.1:p2:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.1:p3:*:*:*:*:*:*
    • (no CPE)range: 14.1-RELEASE
  • FreeBSD/ctlllm-create

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.