Known escape exploits

Public bhyve escapes have targeted specific device models, including the e1000 network adapter and the block and framebuffer emulation, reported as FreeBSD security advisories. The device models are the same class of user-space emulation surface as QEMU's, so the techniques transfer, and bhyve's smaller device set focuses the surface.

text
Recurring bhyve escape surfaces:
- e1000 network adapter
- Block / AHCI emulation
- The framebuffer / display
- virtio devices

Exploitation notes#

  • Reachability depends on the guest's configured devices; a minimal guest exposes fewer models.
  • Escapes land in the host bhyve process, then escalate within FreeBSD; Capsicum confinement bounds a well-configured host.
  • The surface map is in Guest to host escape.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more