CVE-2020-24718: High severity freebsd kernel vulnerability
bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCSHOSTRIP.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24718?
CVE-2020-24718 is a vulnerability in bhyve, as used in FreeBSD through 12.1 and illumos, that allows a root user in a container on an Intel system to gain privileges by modifying VMCS_HO.
How does CVE-2020-24718 impact FreeBSD and illumos?
CVE-2020-24718 impacts FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04).
What is the severity of CVE-2020-24718?
CVE-2020-24718 has a severity rating of 8.2 (high).
How can an attacker exploit CVE-2020-24718?
An attacker can exploit CVE-2020-24718 by being a root user in a container on an Intel system and modifying VMCS_HO to gain privileges.
Where can I find more information about CVE-2020-24718?
You can find more information about CVE-2020-24718 in the references provided: [GitHub](https://github.com/illumos/illumos-gate/blob/84971882a96ac0fecd538b02208054a872ff8af3/usr/src/uts/i86pc/io/vmm/intel/vmcs.c#L246-L249), [FreeBSD Security Advisory](https://security.FreeBSD.org/advisories/FreeBSD-SA-20:28.bhyve_vmcs.asc), and [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20201016-0002/).