Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 9: MGASA-2025-0002 Critical: VirtualBox & kmod-virtualbox Compromise

mageia
Calendar Grey January 4, 2025
Dist Mageia Esm H88
SECURITY-UPDATE-2025-0010 for VMware & kernel-module-vmware addresses serious vulnerabilities. Ensure safety with the newest fixes.
Vulnerabilities were found in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Summary

Vulnerabilities were found in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are prior to 7.0.22 and prior to 7.1.2. A difficult to exploit vulnerability allows a high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise an Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VirtualBox VMs. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

References

- https://bugs.mageia.org/show_bug.cgi?id=33754

- https://www.oracle.com/security-alerts/cpuoct2024.html#AppendixOVIR

-

- https://www.cve.org/CVERecord?id=CVE-2024-21259

- https://www.cve.org/CVERecord?id=CVE-2024-21263

- https://www.cve.org/CVERecord?id=CVE-2024-21273

- https://www.cve.org/CVERecord?id=CVE-2024-21248

- https://www.cve.org/CVERecord?id=CVE-2024-21253

Resolution

SRPMS

- 9/core/virtualbox-7.0.22-1.mga9

- 9/core/kmod-virtualbox-7.0.22-62.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 04 Jan 2025
URL: https://advisories.mageia.org/MGASA-2025-0002.html
Type: security
CVE: CVE-2024-21259, CVE-2024-21263, CVE-2024-21273, CVE-2024-21248, CVE-2024-21253

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here