Guest to host escape

Each bhyve guest is served by a bhyve process on the host that emulates its devices in user space, much like QEMU. Those device models parse guest-controlled input, so memory-corruption flaws in the virtio devices, the e1000 network adapter, the framebuffer, or the USB and block emulation let a guest execute code in the host bhyve process.

text
bhyve guest escape surfaces (reachable from a guest):
- virtio devices (net, block, console)
- e1000 network adapter
- The framebuffer / display
- USB and AHCI/block emulation

Exploitation notes#

  • Code execution lands in the host bhyve process; FreeBSD mitigations and Capsicum capability-mode confinement, where used, limit the outcome, so check the host's confinement.
  • The device set is configured per VM, so reachable surface depends on which emulated devices the guest has.
  • Named instances are under Known escape exploits.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more