Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia 8 MGASA-2021-0385 Critical: VirtualBox Dos Attack Advisory

mageia
Calendar Grey July 27, 2021
Dist Mageia Esm H88
Mageia releases VirtualBox 6.1.24 to fix major vulnerabilities. Protect your devices immediately!
This update provides the upstream 6.1.24 maintenance release that fixes atleast the following security vulnerabilities: An easily exploitable vulnerability in the Oracle VM Virtua...

Summary

This update provides the upstream 6.1.24 maintenance release that fixes atleast the following security vulnerabilities:
An easily exploitable vulnerability in the Oracle VM VirtualBox (component: Core) prior to 6.1.24 allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox (CVE-2021-2409).
An easily exploitable vulnerability in the Oracle VM VirtualBox (component: Core) prior to 6.1.24 allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a han...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=29279

- https://www.oracle.com/security-alerts/cpujul2021.html#AppendixOVIR

-

- https://www.cve.org/CVERecord?id=CVE-2021-2409

- https://www.cve.org/CVERecord?id=CVE-2021-2442

- https://www.cve.org/CVERecord?id=CVE-2021-2443

- https://www.cve.org/CVERecord?id=CVE-2021-2454

Resolution

SRPMS

- 8/core/virtualbox-6.1.24-1.mga8

- 8/core/kmod-virtualbox-6.1.24-1.1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 27 Jul 2021
URL: https://advisories.mageia.org/MGASA-2021-0385.html
Type: security
CVE: CVE-2021-2409, CVE-2021-2442, CVE-2021-2443, CVE-2021-2454

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here