Each bhyve guest is served by a bhyve process on the host that emulates its devices in user space, much like QEMU. Those device models parse guest-controlled input, so memory-corruption flaws in the virtio devices, the e1000 network adapter, the framebuffer, or the USB and block emulation let a guest execute code in the host bhyve process.
bhyve guest escape surfaces (reachable from a guest):
- virtio devices (net, block, console)
- e1000 network adapter
- The framebuffer / display
- USB and AHCI/block emulation
Exploitation notes#
- Code execution lands in the host
bhyveprocess; FreeBSD mitigations and Capsicum capability-mode confinement, where used, limit the outcome, so check the host's confinement. - The device set is configured per VM, so reachable surface depends on which emulated devices the guest has.
- Named instances are under Known escape exploits.