An insufficient boundary validation in the USB code could lead to an out-of-bounds read on the heap, which could potentially lead to an arbitrary write and remote code execution.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
References

Wed, 25 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 20 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Freebsd
Freebsd freebsd
CPEs cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*
Vendors & Products Freebsd
Freebsd freebsd
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 20 Sep 2024 08:00:00 +0000

Type Values Removed Values Added
Description An insufficient boundary validation in the USB code could lead to an out-of-bounds read on the heap, which could potentially lead to an arbitrary write and remote code execution.
Title bhyve(8) out-of-bounds read access via XHCI emulation
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: freebsd

Published:

Updated: 2024-09-26T15:03:10.183Z

Reserved: 2024-08-27T16:30:55.996Z

Link: CVE-2024-41721

cve-icon Vulnrichment

Updated: 2024-09-26T15:03:10.183Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-20T08:15:11.323

Modified: 2024-11-21T09:33:03.463

Link: CVE-2024-41721

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.