Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

openSUSE Leap 15.4: 2023:0033-1 Important VirtualBox Multiple Threat Fixes

opensuse
Calendar Grey January 29, 2023
Dist Opensuse Esm H88
VirtualBox has rolled out a crucial patch addressing several vulnerabilities. Make certain that your openSUSE system is updated accordingly.
An update that fixes 6 vulnerabilities is now available

Description

This update for virtualbox fixes the following issues:

VirtualBox 7.0.6 (released January 17 2023)

This is a maintenance release. The following items were fixed and/or

added: [1]

- VMM: Fixed guru running the FreeBSD loader on older Intel CPUs without

unrestricted guest support (bug #21332)

- GUI: Fixed virtual machines grouping when VM was created or modified in

command line (bugs #11500, #20933)

- GUI: Introduced generic changes in settings dialogs

- VirtioNet: Fixed broken network after loading saved state (bug #21172)

- Storage: Added support for increasing the size of the following VMDK

image variants: monolithicFlat, monolithicSparse, twoGbMaxExtentSparse,

twoGbMaxExtentFlat

- VBoxManage: Added missing --directory switch for guestcontrol mktemp

command

- Mouse Integration: Guest was provided with extended host mouse state

(bug #21139)

- DnD: Introduced generic improvements

- Guest Control: Fixed handling...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.4:

zypper in -t patch openSUSE-2023-33=1

Package List

- openSUSE Leap 15.4 (x86_64):

python3-virtualbox-7.0.6-lp154.2.26.2

python3-virtualbox-debuginfo-7.0.6-lp154.2.26.2

virtualbox-7.0.6-lp154.2.26.2

virtualbox-debuginfo-7.0.6-lp154.2.26.2

virtualbox-debugsource-7.0.6-lp154.2.26.2

virtualbox-devel-7.0.6-lp154.2.26.2

virtualbox-guest-tools-7.0.6-lp154.2.26.2

virtualbox-guest-tools-debuginfo-7.0.6-lp154.2.26.2

virtualbox-kmp-debugsource-7.0.6-lp154.2.26.2

virtualbox-kmp-default-7.0.6_k5.14.21_150400.24.41-lp154.2.26.2

virtualbox-kmp-default-debuginfo-7.0.6_k5.14.21_150400.24.41-lp154.2.26.2

virtualbox-qt-7.0.6-lp154.2.26.2

virtualbox-qt-debuginfo-7.0.6-lp154.2.26.2

virtualbox-vnc-7.0.6-lp154.2.26.2

virtualbox-websrv-7.0.6-lp154.2.26.2

virtualbox-websrv-debuginfo-7.0.6-lp154.2.26.2

- openSUSE Leap 15.4 (noarch):

virtualbox-guest-desktop-icons-7.0.6-lp154.2.26.2

virtualbox-guest-source-7.0.6-lp154.2.26.2

virtualbox-host-source-7.0.6-lp154.2.26.2

References

https://www.suse.com/security/cve/CVE-2023-21884.html

https://www.suse.com/security/cve/CVE-2023-21885.html

https://www.suse.com/security/cve/CVE-2023-21886.html

https://www.suse.com/security/cve/CVE-2023-21889.html

https://www.suse.com/security/cve/CVE-2023-21898.html

https://www.suse.com/security/cve/CVE-2023-21899.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2023:0033-1
Rating: important
Affected Products: openSUSE Leap 15.4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here