"Bhyve is a hypervisor for FreeBSD. This blogpost will describe how a limited OOB write vulnerability in an Adapter Emulator can be turned into code execution allowing to escape from the guest machine"
https://www.synacktiv.com/publications/escaping-from-bhyve.html
@lupyuen the vulnerability appears to be in the emulated e1000 card. This makes the impact of this issue much less critical since this driver is rarely used.