MGASA-2022-0038 - Updated virtualbox packages fix security vulnerability

Publication date: 26 Jan 2022
URL: https://advisories.mageia.org/MGASA-2022-0038.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2022-21295

Updated virtualbox packages fix security vulnerability:

Vulnerability in the Oracle VM VirtualBoxp rior to 6.1.32 contains an 
easily exploitable vulnerability allows low privileged attacker with logon
to the infrastructure where Oracle VM VirtualBox executes to compromise
Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, 
attacks may significantly impact additional products. Successful attacks
of this vulnerability can result in unauthorized read access to a subset
of Oracle VM VirtualBox accessible data (CVE-2022-21295).

For other fixes in this update, see the referenced changelog.

References:
- https://bugs.mageia.org/show_bug.cgi?id=29918
- https://www.oracle.com/security-alerts/cpujan2022.html#AppendixOVIR
- https://www.virtualbox.org/wiki/Changelog-6.1#v32
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21295

SRPMS:
- 8/core/virtualbox-6.1.32-1.mga8
- 8/core/kmod-virtualbox-6.1.32-1.mga8