Source: virtualbox Version: 7.2.8-dfsg-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for virtualbox. CVE-2026-47041[0]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.12. Easily exploitable vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in unauthorized ability to cause a | hang or frequently repeatable crash (complete DOS) of Oracle VM | VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS | Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H). CVE-2026-47043[1]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.12. Easily exploitable vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in unauthorized read access to a | subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score | 3.2 (Confidentiality impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N). CVE-2026-47044[2]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.12. Easily exploitable vulnerability allows low | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. Successful | attacks of this vulnerability can result in unauthorized ability to | cause a hang or frequently repeatable crash (complete DOS) of Oracle | VM VirtualBox. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS | Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). CVE-2026-47047[3]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.12. Easily exploitable vulnerability allows low | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. Successful | attacks of this vulnerability can result in takeover of Oracle VM | VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and | Availability impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). CVE-2026-47050[4]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.8. Easily exploitable vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. Successful | attacks require human interaction from a person other than the | attacker and while the vulnerability is in Oracle VM VirtualBox, | attacks may significantly impact additional products (scope change). | Successful attacks of this vulnerability can result in unauthorized | creation, deletion or modification access to critical data or all | Oracle VM VirtualBox accessible data and unauthorized ability to | cause a hang or frequently repeatable crash (complete DOS) of Oracle | VM VirtualBox. CVSS 3.1 Base Score 7.4 (Integrity and Availability | impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H). CVE-2026-47053[5]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.12. Easily exploitable vulnerability allows low | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. Successful | attacks require human interaction from a person other than the | attacker. Successful attacks of this vulnerability can result in | unauthorized creation, deletion or modification access to critical | data or all Oracle VM VirtualBox accessible data and unauthorized | ability to cause a partial denial of service (partial DOS) of Oracle | VM VirtualBox. CVSS 3.1 Base Score 5.6 (Integrity and Availability | impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L). CVE-2026-47054[6]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.12. Easily exploitable vulnerability allows low | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. Successful | attacks of this vulnerability can result in takeover of Oracle VM | VirtualBox. Note: This vulnerability applies to Windows host only. | CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability | impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). CVE-2026-47055[7]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.12. Easily exploitable vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in unauthorized update, insert or | delete access to some of Oracle VM VirtualBox accessible data. CVSS | 3.1 Base Score 3.2 (Integrity impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N). CVE-2026-47062[8]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.12. Easily exploitable vulnerability allows low | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. Successful | attacks of this vulnerability can result in unauthorized ability to | cause a hang or frequently repeatable crash (complete DOS) of Oracle | VM VirtualBox. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS | Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). CVE-2026-60150[9]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.12. Easily exploitable vulnerability allows low | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. Successful | attacks of this vulnerability can result in takeover of Oracle VM | VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and | Availability impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). CVE-2026-60155[10]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.12. Difficult to exploit vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in takeover of Oracle VM VirtualBox. | CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability | impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H). CVE-2026-60158[11]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.12. Difficult to exploit vulnerability allows low | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in unauthorized creation, deletion or | modification access to critical data or all Oracle VM VirtualBox | accessible data and unauthorized ability to cause a partial denial | of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base | Score 6.4 (Integrity and Availability impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L). CVE-2026-60159[12]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.12. Difficult to exploit vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in takeover of Oracle VM VirtualBox. | CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability | impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H). CVE-2026-60160[13]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.12. Easily exploitable vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in unauthorized read access to a | subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score | 3.2 (Confidentiality impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N). CVE-2026-60161[14]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.12. Easily exploitable vulnerability allows | unauthenticated attacker with logon to the infrastructure where | Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. | Successful attacks require human interaction from a person other | than the attacker. Successful attacks of this vulnerability can | result in unauthorized ability to cause a hang or frequently | repeatable crash (complete DOS) of Oracle VM VirtualBox as well as | unauthorized update, insert or delete access to some of Oracle VM | VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and | Availability impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H). CVE-2026-60162[15]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.12. Difficult to exploit vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in unauthorized access to critical | data or complete access to all Oracle VM VirtualBox accessible data | and unauthorized ability to cause a partial denial of service | (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.1 | (Confidentiality and Availability impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L). If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-47041 https://www.cve.org/CVERecord?id=CVE-2026-47041 [1] https://security-tracker.debian.org/tracker/CVE-2026-47043 https://www.cve.org/CVERecord?id=CVE-2026-47043 [2] https://security-tracker.debian.org/tracker/CVE-2026-47044 https://www.cve.org/CVERecord?id=CVE-2026-47044 [3] https://security-tracker.debian.org/tracker/CVE-2026-47047 https://www.cve.org/CVERecord?id=CVE-2026-47047 [4] https://security-tracker.debian.org/tracker/CVE-2026-47050 https://www.cve.org/CVERecord?id=CVE-2026-47050 [5] https://security-tracker.debian.org/tracker/CVE-2026-47053 https://www.cve.org/CVERecord?id=CVE-2026-47053 [6] https://security-tracker.debian.org/tracker/CVE-2026-47054 https://www.cve.org/CVERecord?id=CVE-2026-47054 [7] https://security-tracker.debian.org/tracker/CVE-2026-47055 https://www.cve.org/CVERecord?id=CVE-2026-47055 [8] https://security-tracker.debian.org/tracker/CVE-2026-47062 https://www.cve.org/CVERecord?id=CVE-2026-47062 [9] https://security-tracker.debian.org/tracker/CVE-2026-60150 https://www.cve.org/CVERecord?id=CVE-2026-60150 [10] https://security-tracker.debian.org/tracker/CVE-2026-60155 https://www.cve.org/CVERecord?id=CVE-2026-60155 [11] https://security-tracker.debian.org/tracker/CVE-2026-60158 https://www.cve.org/CVERecord?id=CVE-2026-60158 [12] https://security-tracker.debian.org/tracker/CVE-2026-60159 https://www.cve.org/CVERecord?id=CVE-2026-60159 [13] https://security-tracker.debian.org/tracker/CVE-2026-60160 https://www.cve.org/CVERecord?id=CVE-2026-60160 [14] https://security-tracker.debian.org/tracker/CVE-2026-60161 https://www.cve.org/CVERecord?id=CVE-2026-60161 [15] https://security-tracker.debian.org/tracker/CVE-2026-60162 https://www.cve.org/CVERecord?id=CVE-2026-60162 Regards, Salvatore

