|
|
Log in / Subscribe / Register

Mageia alert MGASA-2022-0265 (virtualbox)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2022-0265: Updated virtualbox packages fix security vulnerabilities
Date:  Mon, 25 Jul 2022 11:51:59 +0200
Message-ID:  <20220725095159.DB7CDA0F67@duvel.mageia.org>
Archive-link:  Article

MGASA-2022-0265 - Updated virtualbox packages fix security vulnerabilities Publication date: 25 Jul 2022 URL: https://advisories.mageia.org/MGASA-2022-0265.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-21554, CVE-2022-21571 Description: This update provides the upstream 6.1.36 maintenance release that fixes at least the following security vulnerabilities: A vulnerability in the Oracle VM VirtualBox prior to 6.1.36 contains an easily exploitable vulnerability that allows a high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox (CVE-2022-21554). A vulnerability in the Oracle VM VirtualBox prior to 6.1.36 contains an easily exploitable vulnerability that allows a high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox (CVE-2022-21571). For other fixes in this update, see the referenced changeelog References: - https://bugs.mageia.org/show_bug.cgi?id=30657 - https://www.oracle.com/security-alerts/cpujul2022.html#Ap... - https://www.virtualbox.org/wiki/Changelog-6.1#v36 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2... SRPMS: - 8/core/virtualbox-6.1.36-1.mga8 - 8/core/kmod-virtualbox-6.1.36-1.mga8


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds