MGASA-2022-0038 - Updated virtualbox packages fix security vulnerability

Publication date: 26 Jan 2022
URL: https://advisories.mageia.org/MGASA-2022-0038.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2022-21295

Updated virtualbox packages fix security vulnerability:

Vulnerability in the Oracle VM VirtualBoxp rior to 6.1.32 contains an 
easily exploitable vulnerability allows low privileged attacker with logon
to the infrastructure where Oracle VM VirtualBox executes to compromise
Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, 
attacks may significantly impact additional products. Successful attacks
of this vulnerability can result in unauthorized read access to a subset
of Oracle VM VirtualBox accessible data (CVE-2022-21295).

For other fixes in this update, see the referenced changelog.

References:
- https://bugs.mageia.org/show_bug.cgi?id=29918
- https://www.oracle.com/security-alerts/cpujan2022.html#AppendixOVIR
- https://www.virtualbox.org/wiki/Changelog-6.1#v32
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21295

SRPMS:
- 8/core/virtualbox-6.1.32-1.mga8
- 8/core/kmod-virtualbox-6.1.32-1.mga8

Mageia 2022-0038: virtualbox security update

Updated virtualbox packages fix security vulnerability: Vulnerability in the Oracle VM VirtualBoxp rior to 6.1.32 contains an easily exploitable vulnerability allows low privileg...

Summary

Updated virtualbox packages fix security vulnerability:
Vulnerability in the Oracle VM VirtualBoxp rior to 6.1.32 contains an easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data (CVE-2022-21295).
For other fixes in this update, see the referenced changelog.

References

- https://bugs.mageia.org/show_bug.cgi?id=29918

- https://www.oracle.com/security-alerts/cpujan2022.html#AppendixOVIR

- https://www.virtualbox.org/wiki/Changelog-6.1#v32

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21295

Resolution

MGASA-2022-0038 - Updated virtualbox packages fix security vulnerability

SRPMS

- 8/core/virtualbox-6.1.32-1.mga8

- 8/core/kmod-virtualbox-6.1.32-1.mga8

Severity
Publication date: 26 Jan 2022
URL: https://advisories.mageia.org/MGASA-2022-0038.html
Type: security
CVE: CVE-2022-21295

Related News