Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 891327 (CVE-2023-21884, CVE-2023-21885, CVE-2023-21886, CVE-2023-21889, CVE-2023-21898, CVE-2023-21899) - <app-emulation/virtualbox-{6.1.42,7.0.6}: multiple vulnerabilities (Oracle CPU Jan 2023)
Summary: <app-emulation/virtualbox-{6.1.42,7.0.6}: multiple vulnerabilities (Oracle CP...
Status: RESOLVED FIXED
Alias: CVE-2023-21884, CVE-2023-21885, CVE-2023-21886, CVE-2023-21889, CVE-2023-21898, CVE-2023-21899
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal critical (vote)
Assignee: Gentoo Security
URL: https://www.oracle.com/security-alert...
Whiteboard: A1 [glsa+]
Keywords: PullRequest
Depends on: 891735 893606
Blocks:
  Show dependency tree
 
Reported: 2023-01-18 18:29 UTC by John Helmert III
Modified: 2023-10-08 07:08 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-01-18 18:29:55 UTC
CVE-2023-21886:

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are Prior to 6.1.42 and  prior to 7.0.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2023-21898:

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are Prior to 6.1.42 and  prior to 7.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. Note: Applies to VirtualBox VMs running Windows 7 and later. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2023-21899:

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are Prior to 6.1.42 and  prior to 7.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. Note: Applies to VirtualBox VMs running Windows 7 and later. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2023-21884:

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are Prior to 6.1.42 and  prior to 7.0.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2023-21885:

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are Prior to 6.1.42 and  prior to 7.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle VM VirtualBox accessible data. Note: Applies to Windows only. CVSS 3.1 Base Score 3.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).

CVE-2023-21889:

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are Prior to 6.1.42 and  prior to 7.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).

Please bump to 6.1.42 and 7.0.6.
Comment 1 Larry the Git Cow gentoo-dev 2023-01-22 09:59:56 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e973eb4dc3188909a58cee8cb6fb7b6ae199c51f

commit e973eb4dc3188909a58cee8cb6fb7b6ae199c51f
Author:     Viorel Munteanu <ceamac@gentoo.org>
AuthorDate: 2023-01-18 20:32:28 +0000
Commit:     Viorel Munteanu <ceamac@gentoo.org>
CommitDate: 2023-01-22 09:55:03 +0000

    app-emulation/virtualbox: add 7.0.6
    
    Closes: https://bugs.gentoo.org/891485
    Bug: https://bugs.gentoo.org/891327
    Signed-off-by: Viorel Munteanu <ceamac@gentoo.org>

 app-emulation/virtualbox/Manifest                |   1 +
 app-emulation/virtualbox/virtualbox-7.0.6.ebuild | 721 +++++++++++++++++++++++
 2 files changed, 722 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=8ab48ff7052883fca95982dec5da2b8192f42cd7

commit 8ab48ff7052883fca95982dec5da2b8192f42cd7
Author:     Viorel Munteanu <ceamac@gentoo.org>
AuthorDate: 2023-01-18 19:52:29 +0000
Commit:     Viorel Munteanu <ceamac@gentoo.org>
CommitDate: 2023-01-22 09:55:03 +0000

    app-emulation/virtualbox: add 6.1.42
    
    Bug: https://bugs.gentoo.org/891327
    Signed-off-by: Viorel Munteanu <ceamac@gentoo.org>

 app-emulation/virtualbox/Manifest                 |   1 +
 app-emulation/virtualbox/virtualbox-6.1.42.ebuild | 663 ++++++++++++++++++++++
 2 files changed, 664 insertions(+)
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-01-23 04:28:56 UTC
Thanks! Please stabilize when ready.
Comment 3 Larry the Git Cow gentoo-dev 2023-02-21 15:06:17 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=2511796b4a83154d364237b58b3f8ce7f0675554

commit 2511796b4a83154d364237b58b3f8ce7f0675554
Author:     Viorel Munteanu <ceamac@gentoo.org>
AuthorDate: 2023-02-21 14:27:18 +0000
Commit:     Viorel Munteanu <ceamac@gentoo.org>
CommitDate: 2023-02-21 15:04:23 +0000

    app-emulation/virtualbox: drop 7.0.4-r1
    
    Bug: https://bugs.gentoo.org/891327
    Signed-off-by: Viorel Munteanu <ceamac@gentoo.org>

 app-emulation/virtualbox/Manifest                  |   1 -
 .../virtualbox/virtualbox-7.0.4-r1.ebuild          | 705 ---------------------
 2 files changed, 706 deletions(-)
Comment 4 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-02-25 16:59:00 UTC
Thanks!
Comment 5 Larry the Git Cow gentoo-dev 2023-10-08 07:07:51 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=4c14f02c4db85c538fae2fe557538f046baa6646

commit 4c14f02c4db85c538fae2fe557538f046baa6646
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2023-10-08 07:06:19 +0000
Commit:     Hans de Graaff <graaff@gentoo.org>
CommitDate: 2023-10-08 07:07:44 +0000

    [ GLSA 202310-07 ] Oracle VirtualBox: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/891327
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Hans de Graaff <graaff@gentoo.org>

 glsa-202310-07.xml | 58 ++++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 58 insertions(+)