← back
CVE-2024-51566mediumCWE-1285

bhyve(8) NVMe driver to guest-induced infinite loops.

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 0.4%
exploitation probability
0.4%top 69% of all CVEs
observed exploitation
nono source reports it
In short

The NVMe driver in bhyve virtual machine can be forced into infinite loops by a malicious guest operating system, potentially freezing the hypervisor or consuming excessive CPU resources.

Technical detail

A guest VM can trigger infinite loops in the bhyve NVMe queue processing logic through specially crafted NVMe commands, causing denial of service on the hypervisor without requiring elevated privileges within the guest. The vulnerability stems from insufficient loop termination conditions in queue processing.

Summary generated and translated by AI from the official description.
The NVMe driver queue processing is vulernable to guest-induced infinite loops.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Affected products
FreeBSD · FreeBSD