CVE-2024-25940: bhyveload(8) host file access

Published Feb 15, 2024
·
Updated

bhyveload -h <host-path> may be used to grant loader access to the <host-path> directory tree on the host. Affected versions of bhyveload(8) do not make any attempt to restrict loader's access to <host-path>, allowing the loader to read any file the host user has access to. In the bhyveload(8) model, the host supplies a userboot.so to boot with, but the loader scripts generally come from the guest image. A maliciously crafted script could be used to exfiltrate sensitive data from the host accessible to the user running bhyhveload(8), which is often the system root.

Affected Software

19 affected components
FreeBSD FreeBSD<13.2
FreeBSD FreeBSD>=13.3<14.0
FreeBSD FreeBSD=13.2-p1
FreeBSD FreeBSD=13.2-p2
FreeBSD FreeBSD=13.2-p3
FreeBSD FreeBSD=13.2-p4
FreeBSD FreeBSD=13.2-p5
FreeBSD FreeBSD=13.2-p6
FreeBSD FreeBSD=13.2-p7
FreeBSD FreeBSD=13.2-p8
FreeBSD FreeBSD=13.2-p9
FreeBSD FreeBSD=14.0-beta5
FreeBSD FreeBSD=14.0-p1
FreeBSD FreeBSD=14.0-p2
FreeBSD FreeBSD=14.0-p3
FreeBSD FreeBSD=14.0-p4
FreeBSD FreeBSD=14.0-rc3
FreeBSD FreeBSD=14.0-rc4-p1
FreeBSD bhyveload

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Avoid invoking `bhyveload -h <host-path>` unless you must grant the loader access to that host directory tree; otherwise loader scripts can read any host files the host user can access.

    bhyveload(8) -h <host-path> (host path access) = Do not use -h <host-path> except when strictly required

Event History

Feb 15, 2024
CVE Published
via MITRE·04:21 AM
Data Sourced
via MITRE·04:21 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-25940?

CVE-2024-25940 has been classified as a high-severity vulnerability due to its potential to expose sensitive files on the host system.

2

How do I fix CVE-2024-25940?

To mitigate CVE-2024-25940, ensure you upgrade to a patched version of bhyveload that restricts access to the host-path directory tree.

3

What systems are affected by CVE-2024-25940?

CVE-2024-25940 affects the FreeBSD bhyveload versions that do not implement restrictions on the loader access to the host-path.

4

What is the impact of CVE-2024-25940?

The impact of CVE-2024-25940 allows unauthorized file access, which could lead to the exposure of sensitive data on the host.

5

Are there any workarounds for CVE-2024-25940?

While updates are recommended for CVE-2024-25940, users may temporarily limit access permissions for the host-path to mitigate risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203