← back
CVE-2024-51564highCWE-1285

bhyve(8) infinite loop in the hda audio driver

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
In short

A guest operating system can cause the bhyve hypervisor's audio driver to enter an infinite loop, potentially freezing the system or consuming all CPU resources. This happens because the driver doesn't properly validate certain audio-related requests.

Technical detail

An attacker with guest OS access can trigger an infinite loop vulnerability in the bhyve hda audio driver through malformed audio device requests. The vulnerability stems from improper input validation in the audio processing logic, allowing guest-controlled data to cause unbounded iteration. Successful exploitation results in denial of service via CPU exhaustion on the host hypervisor.

Summary generated and translated by AI from the official description.
A guest can trigger an infinite loop in the hda audio driver.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
FreeBSD · FreeBSD