Beveiligingsadvies

CVE-2020-24718

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-09-25 03:49:02
Laatst bijgewerkt 2024-08-04 15:19:09
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.