CVE-2024-8178
The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it. Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process. A malicious iSCSI initiator could achieve remote code execution on the iSCSI target host.
Scoring
- CVSS base score
- 0.12
- EPSS probability
- 0.60%
- CWE
- CWE-908, CWE-909
- Published
- 2024-09-05
- Last modified
- 2026-03-13
Affected products
- FreeBSD FreeBSD
- FreeBSD FreeBSD
- FreeBSD FreeBSD
Weakness type
Related vulnerabilities
- CVE-2026-87555 — Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a...
- CVE-2026-87576 — Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a...
- CVE-2026-87497 — Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87642 — Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87456 — Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87647 — Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who...
- CVE-2026-81958 — Microsoft Excel Information Disclosure Vulnerability
- CVE-2026-81391 — Microsoft Excel Information Disclosure Vulnerability