Updated virtualbox packages fix security vulnerability:
Vulnerability in the Oracle VM VirtualBoxp rior to 6.1.32 contains an
easily exploitable vulnerability allows low privileged attacker with logon
to the infrastructure where Oracle VM VirtualBox executes to compromise
Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox,
attacks may significantly impact additional products. Successful attacks
of this vulnerability can result in unauthorized read access to a subset
of Oracle VM VirtualBox accessible data (CVE-2022-21295).
For other fixes in this update, see the referenced changelog.
- https://bugs.mageia.org/show_bug.cgi?id=29918
- https://www.oracle.com/security-alerts/cpujan2022.html#AppendixOVIR
-
- https://www.cve.org/CVERecord?id=CVE-2022-21295
- 8/core/virtualbox-6.1.32-1.mga8
- 8/core/kmod-virtualbox-6.1.32-1.mga8
Get the latest Linux and open source security news straight to your inbox.