A guest can trigger an infinite loop in the hda audio driver.
Several vulnerabilities were found in the bhyve hypervisor's device models. The NVMe driver function nvme_opc_get_log_page is vulnerable to a buffer over- read from a guest-controlled value. The virtio_vq_recordon function is subject to a time-of-check to time-of-use (TOCTOU) race condition. A guest can trigger an infinite loop in the hda audio driver. The hda driver is vulnerable to a buffer over-read from a guest-controlled value. The NVMe driver queue processing is vulernable to guest-induced infinite loops. Malicious guest virtual machines may be able to perform a denial of service (DoS) of the bhyve host, and may read memory within the bhyve process that they should not be able to access.