CVE-2024-51564: high-severity vulnerability in FreeBSD
bhyve(8) infinite loop in the hda audio driver
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
A guest operating system can cause the bhyve hypervisor's audio driver to enter an infinite loop, potentially freezing the system or consuming all CPU resources. This happens because the driver doesn't properly validate certain audio-related requests.
An attacker with guest OS access can trigger an infinite loop vulnerability in the bhyve hda audio driver through malformed audio device requests. The vulnerability stems from improper input validation in the audio processing logic, allowing guest-controlled data to cause unbounded iteration. Successful exploitation results in denial of service via CPU exhaustion on the host hypervisor.
In the same product, most dangerous first.