In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, certain VirtIO-based device models in bhyve failed to handle errors when fetching I/O descriptors. A malicious guest may cause the device model to operate on uninitialized I/O vectors leading to memory corruption, crashing of the bhyve process, and possibly arbitrary code execution in the bhyve process.
The product uses or accesses a resource that has not been initialized.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Freebsd | Freebsd | 11.4 (including) | 11.4 (including) |
Freebsd | Freebsd | 11.4-p1 (including) | 11.4-p1 (including) |
Freebsd | Freebsd | 11.4-p10 (including) | 11.4-p10 (including) |
Freebsd | Freebsd | 11.4-p11 (including) | 11.4-p11 (including) |
Freebsd | Freebsd | 11.4-p12 (including) | 11.4-p12 (including) |
Freebsd | Freebsd | 11.4-p13 (including) | 11.4-p13 (including) |
Freebsd | Freebsd | 11.4-p2 (including) | 11.4-p2 (including) |
Freebsd | Freebsd | 11.4-p3 (including) | 11.4-p3 (including) |
Freebsd | Freebsd | 11.4-p4 (including) | 11.4-p4 (including) |
Freebsd | Freebsd | 11.4-p5 (including) | 11.4-p5 (including) |
Freebsd | Freebsd | 11.4-p6 (including) | 11.4-p6 (including) |
Freebsd | Freebsd | 11.4-p7 (including) | 11.4-p7 (including) |
Freebsd | Freebsd | 11.4-p8 (including) | 11.4-p8 (including) |
Freebsd | Freebsd | 11.4-p9 (including) | 11.4-p9 (including) |
Freebsd | Freebsd | 12.2 (including) | 12.2 (including) |
Freebsd | Freebsd | 12.2-p1 (including) | 12.2-p1 (including) |
Freebsd | Freebsd | 12.2-p10 (including) | 12.2-p10 (including) |
Freebsd | Freebsd | 12.2-p2 (including) | 12.2-p2 (including) |
Freebsd | Freebsd | 12.2-p3 (including) | 12.2-p3 (including) |
Freebsd | Freebsd | 12.2-p4 (including) | 12.2-p4 (including) |
Freebsd | Freebsd | 12.2-p5 (including) | 12.2-p5 (including) |
Freebsd | Freebsd | 12.2-p6 (including) | 12.2-p6 (including) |
Freebsd | Freebsd | 12.2-p7 (including) | 12.2-p7 (including) |
Freebsd | Freebsd | 12.2-p8 (including) | 12.2-p8 (including) |
Freebsd | Freebsd | 12.2-p9 (including) | 12.2-p9 (including) |
Freebsd | Freebsd | 13.0 (including) | 13.0 (including) |
Freebsd | Freebsd | 13.0-p1 (including) | 13.0-p1 (including) |
Freebsd | Freebsd | 13.0-p2 (including) | 13.0-p2 (including) |
Freebsd | Freebsd | 13.0-p3 (including) | 13.0-p3 (including) |