Executive brief
Bitdefender Napoca is a bare-metal hypervisor used to manage and isolate virtual machines. A vulnerability in how it handles memory map requests allows a malicious guest operating system to write data outside of its assigned memory area and into the hypervisor's own memory. This could allow an attacker to compromise the entire host system, though the product is now end-of-life and will not receive a fix.
Technical details
An out-of-bounds write vulnerability exists in the BIOS INT 0x15 / E820 memory map handler within `napoca/guests/bios_handlers.c`. The root cause is a failure to validate destination offsets computed from guest-controlled ES and EDI register values, which can exceed the 1MB RealModeMemory allocation. By invoking the interrupt with specific register values (AX=0xE820, ES=0xFFFF, EDI=0xFFFF), a malicious guest in real mode can write up to 20 bytes into the hypervisor heap. This vulnerability is classified as CWE-787. No patch is available as the product is end-of-life.
Affected products
- Bitdefender Napoca bare-metal hypervisor
Timeline
- 2026-06-02: disclosed
- 2026-06-02: advisory