MGASA-2024-0232 - Updated virtualbox &  kmod-virtualbox packages fix security vulnerabilities

Publication date: 24 Jun 2024
URL: https://advisories.mageia.org/MGASA-2024-0232.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-21103,
     CVE-2024-21106,
     CVE-2024-21107,
     CVE-2024-21108,
     CVE-2024-21109,
     CVE-2024-21110,
     CVE-2024-21111,
     CVE-2024-21112,
     CVE-2024-21113,
     CVE-2024-21114,
     CVE-2024-21115,
     CVE-2024-21116,
     CVE-2024-21121

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). Supported versions that are affected
are Prior to 7.0.16. Easily exploitable vulnerability allows low
privileged attacker with logon to the infrastructure where Oracle VM
VirtualBox executes to compromise Oracle VM VirtualBox. Successful
attacks of this vulnerability can result in takeover of Oracle VM
VirtualBox. Note: This vulnerability applies to Linux hosts only. CVSS
3.1 Base Score 7.8 (Confidentiality, Integrity and Availability
impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

References:
- https://bugs.mageia.org/show_bug.cgi?id=33273
- https://www.oracle.com/security-alerts/cpuapr2024.html#AppendixOVIR
- https://www.virtualbox.org/wiki/Changelog-7.0#v16
- https://www.virtualbox.org/wiki/Changelog-7.0#v18
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21103
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21106
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21107
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21108
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21109
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21110
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21111
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21112
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21113
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21114
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21115
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21116
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21121

SRPMS:
- 9/core/virtualbox-7.0.18-1.mga9
- 9/core/kmod-virtualbox-7.0.18-48.mga9

Critical Security Updates for Oracle VM VirtualBox: Addressing Major Vulnerabilities

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Summary

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Linux hosts only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

References

- https://bugs.mageia.org/show_bug.cgi?id=33273

- https://www.oracle.com/security-alerts/cpuapr2024.html#AppendixOVIR

- https://www.virtualbox.org/wiki/Changelog-7.0#v16

- https://www.virtualbox.org/wiki/Changelog-7.0#v18

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21103

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21106

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21107

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21108

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21109

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21110

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21111

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21112

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21113

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21114

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21115

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21116

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21121

Resolution

MGASA-2024-0232 - Updated virtualbox & kmod-virtualbox packages fix security vulnerabilities

SRPMS

- 9/core/virtualbox-7.0.18-1.mga9

- 9/core/kmod-virtualbox-7.0.18-48.mga9

Severity
Publication date: 24 Jun 2024
URL: https://advisories.mageia.org/MGASA-2024-0232.html
Type: security
CVE: CVE-2024-21103, CVE-2024-21106, CVE-2024-21107, CVE-2024-21108, CVE-2024-21109, CVE-2024-21110, CVE-2024-21111, CVE-2024-21112, CVE-2024-21113, CVE-2024-21114, CVE-2024-21115, CVE-2024-21116, CVE-2024-21121

Related News