[ GLSA 202208-36 ] Oracle VirtualBox: Multiple Vulnerabilities

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <166198897984.12.376556670801611940@ec95405eafab>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202208-36
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: Oracle VirtualBox: Multiple Vulnerabilities
     Date: August 31, 2022
     Bugs: #785445, #803134, #820425, #831440, #839990, #859391
       ID: 202208-36

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been discovered in Oracle Virtualbox, the
worst of which could result in root privilege escalation.

Background
==========

VirtualBox is a powerful virtualization product from Oracle.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  app-emulation/virtualbox   < 6.1.36                    >= 6.1.36
  2  app-emulation/virtualbox-additions< 6.1.36             >= 6.1.36
  3  app-emulation/virtualbox-extpack-oracle< 6.1.36        >= 6.1.36
  4  app-emulation/virtualbox-guest-additions< 6.1.36       >= 6.1.36
  5  app-emulation/virtualbox-modules< 6.1.36               >= 6.1.36

Description
===========

Multiple vulnerabilities have been discovered in VirtualBox. Please
review the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All VirtualBox users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=app-emulation/virtualbox-6.1.36"

References
==========

[ 1 ] CVE-2021-2145
      https://nvd.nist.gov/vuln/detail/CVE-2021-2145
[ 2 ] CVE-2021-2250
      https://nvd.nist.gov/vuln/detail/CVE-2021-2250
[ 3 ] CVE-2021-2264
      https://nvd.nist.gov/vuln/detail/CVE-2021-2264
[ 4 ] CVE-2021-2266
      https://nvd.nist.gov/vuln/detail/CVE-2021-2266
[ 5 ] CVE-2021-2279
      https://nvd.nist.gov/vuln/detail/CVE-2021-2279
[ 6 ] CVE-2021-2280
      https://nvd.nist.gov/vuln/detail/CVE-2021-2280
[ 7 ] CVE-2021-2281
      https://nvd.nist.gov/vuln/detail/CVE-2021-2281
[ 8 ] CVE-2021-2282
      https://nvd.nist.gov/vuln/detail/CVE-2021-2282
[ 9 ] CVE-2021-2283
      https://nvd.nist.gov/vuln/detail/CVE-2021-2283
[ 10 ] CVE-2021-2284
      https://nvd.nist.gov/vuln/detail/CVE-2021-2284
[ 11 ] CVE-2021-2285
      https://nvd.nist.gov/vuln/detail/CVE-2021-2285
[ 12 ] CVE-2021-2286
      https://nvd.nist.gov/vuln/detail/CVE-2021-2286
[ 13 ] CVE-2021-2287
      https://nvd.nist.gov/vuln/detail/CVE-2021-2287
[ 14 ] CVE-2021-2291
      https://nvd.nist.gov/vuln/detail/CVE-2021-2291
[ 15 ] CVE-2021-2296
      https://nvd.nist.gov/vuln/detail/CVE-2021-2296
[ 16 ] CVE-2021-2297
      https://nvd.nist.gov/vuln/detail/CVE-2021-2297
[ 17 ] CVE-2021-2306
      https://nvd.nist.gov/vuln/detail/CVE-2021-2306
[ 18 ] CVE-2021-2309
      https://nvd.nist.gov/vuln/detail/CVE-2021-2309
[ 19 ] CVE-2021-2310
      https://nvd.nist.gov/vuln/detail/CVE-2021-2310
[ 20 ] CVE-2021-2312
      https://nvd.nist.gov/vuln/detail/CVE-2021-2312
[ 21 ] CVE-2021-2409
      https://nvd.nist.gov/vuln/detail/CVE-2021-2409
[ 22 ] CVE-2021-2442
      https://nvd.nist.gov/vuln/detail/CVE-2021-2442
[ 23 ] CVE-2021-2443
      https://nvd.nist.gov/vuln/detail/CVE-2021-2443
[ 24 ] CVE-2021-2454
      https://nvd.nist.gov/vuln/detail/CVE-2021-2454
[ 25 ] CVE-2021-2475
      https://nvd.nist.gov/vuln/detail/CVE-2021-2475
[ 26 ] CVE-2021-35538
      https://nvd.nist.gov/vuln/detail/CVE-2021-35538
[ 27 ] CVE-2021-35540
      https://nvd.nist.gov/vuln/detail/CVE-2021-35540
[ 28 ] CVE-2021-35542
      https://nvd.nist.gov/vuln/detail/CVE-2021-35542
[ 29 ] CVE-2021-35545
      https://nvd.nist.gov/vuln/detail/CVE-2021-35545
[ 30 ] CVE-2022-21394
      https://nvd.nist.gov/vuln/detail/CVE-2022-21394
[ 31 ] CVE-2022-21465
      https://nvd.nist.gov/vuln/detail/CVE-2022-21465
[ 32 ] CVE-2022-21471
      https://nvd.nist.gov/vuln/detail/CVE-2022-21471
[ 33 ] CVE-2022-21487
      https://nvd.nist.gov/vuln/detail/CVE-2022-21487
[ 34 ] CVE-2022-21488
      https://nvd.nist.gov/vuln/detail/CVE-2022-21488
[ 35 ] CVE-2022-21554
      https://nvd.nist.gov/vuln/detail/CVE-2022-21554
[ 36 ] CVE-2022-21571
      https://nvd.nist.gov/vuln/detail/CVE-2022-21571

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202208-36

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2022 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmMP8HMACgkQFMQkOaVy
+9lVcxAAz1KooHl7hoZgILeRIn2e82WIWyzw7+aKHO+Di7y0tfbc1HaCF4ITIHLe
m05p3d4jiddnGZooEPovZd+Urcriy2AIRg57JL2kXb60TZxhkELJUswSuzgF44b4
0O8j1zmSinmli9bApM92Yacip+B8M+0Ww82TfeHcjofUA07/I8eKHx2amCsaLEyi
gbqtQ9X4sJ3axoe5zytCus0SFhEY3VihK5co/uezO6rdAuaEIpFtkwULbu1DMsv+
+Ff/tyfEWkM1TIenw6XpyHUE1jCE+aD1VgouBx8JF9udtJmWeRXdg9f0JlPzKAi9
wdA3/Xsg7WCRMkQA/wUxKXTa0PfAI7dMltV7UuB5vLAqB4WcY0Q2rmTWcTmBtDlk
fR9Npbcb0eRST+nx+q5kNxdagoQTbjD71HTrijNMHdxOnwnIkOo4ibGigI5qaPzJ
ECGKhbF2jhsITfo2+5O2Zgt0YRZY8hlvP/kXQi1Xn+Tld3oZccTTQPrLFdybygjO
5E/UDywXi8ngBH8e7llojGF2FHssA5YKRHsKXTnowdEHx3HxyfL0ZCil2iSuHLwQ
CReImm3WzRZiTRZIMfUr8KfD74M5wc5oRZVkN1GTqOqy8IFjXkmlbcTytnDiqekp
qb1MxXnQ1VbrvhVXd3ufdDiIo5nVRlTDdwGp6PJeqOqZ9bviT6o=
=77Nn
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.