CVE Vulnerabilities

CVE-2024-32668

Off-by-one Error

Published: Sep 05, 2024 | Modified: Nov 21, 2024
CVSS 3.x
8.2
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An insufficient boundary validation in the USB code could lead to an out-of-bounds write on the heap, with data controlled by the caller.

A malicious, privileged software running in a guest VM can exploit the vulnerability to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process.

Weakness

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Affected Software

Name Vendor Start Version End Version
Freebsd Freebsd 13.0 (including) 13.3 (excluding)
Freebsd Freebsd 13.3 (including) 13.3 (including)
Freebsd Freebsd 13.3-p1 (including) 13.3-p1 (including)
Freebsd Freebsd 13.3-p2 (including) 13.3-p2 (including)
Freebsd Freebsd 13.3-p3 (including) 13.3-p3 (including)
Freebsd Freebsd 13.3-p4 (including) 13.3-p4 (including)
Freebsd Freebsd 13.3-p5 (including) 13.3-p5 (including)
Freebsd Freebsd 13.4-beta3 (including) 13.4-beta3 (including)
Freebsd Freebsd 14.0 (including) 14.0 (including)
Freebsd Freebsd 14.0-beta5 (including) 14.0-beta5 (including)
Freebsd Freebsd 14.0-p1 (including) 14.0-p1 (including)
Freebsd Freebsd 14.0-p2 (including) 14.0-p2 (including)
Freebsd Freebsd 14.0-p3 (including) 14.0-p3 (including)
Freebsd Freebsd 14.0-p4 (including) 14.0-p4 (including)
Freebsd Freebsd 14.0-p5 (including) 14.0-p5 (including)
Freebsd Freebsd 14.0-p6 (including) 14.0-p6 (including)
Freebsd Freebsd 14.0-p7 (including) 14.0-p7 (including)
Freebsd Freebsd 14.0-p8 (including) 14.0-p8 (including)
Freebsd Freebsd 14.0-p9 (including) 14.0-p9 (including)
Freebsd Freebsd 14.0-rc3 (including) 14.0-rc3 (including)
Freebsd Freebsd 14.0-rc4-p1 (including) 14.0-rc4-p1 (including)
Freebsd Freebsd 14.1 (including) 14.1 (including)
Freebsd Freebsd 14.1-p1 (including) 14.1-p1 (including)
Freebsd Freebsd 14.1-p2 (including) 14.1-p2 (including)
Freebsd Freebsd 14.1-p3 (including) 14.1-p3 (including)

Potential Mitigations

References