Source: virtualbox
Version: 7.2.8-dfsg-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for virtualbox.

CVE-2026-47041[0]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in unauthorized ability to cause a
| hang or frequently repeatable crash (complete DOS) of Oracle VM
| VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts).  CVSS
| Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).


CVE-2026-47043[1]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in  unauthorized read access to a
| subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score
| 3.2 (Confidentiality impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).


CVE-2026-47044[2]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows low
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  Successful
| attacks of this vulnerability can result in unauthorized ability to
| cause a hang or frequently repeatable crash (complete DOS) of Oracle
| VM VirtualBox. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS
| Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-47047[3]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows low
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  Successful
| attacks of this vulnerability can result in takeover of Oracle VM
| VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and
| Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).


CVE-2026-47050[4]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.8. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  Successful
| attacks require human interaction from a person other than the
| attacker and while the vulnerability is in Oracle VM VirtualBox,
| attacks may significantly impact additional products (scope change).
| Successful attacks of this vulnerability can result in  unauthorized
| creation, deletion or modification access to critical data or all
| Oracle VM VirtualBox accessible data and unauthorized ability to
| cause a hang or frequently repeatable crash (complete DOS) of Oracle
| VM VirtualBox. CVSS 3.1 Base Score 7.4 (Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H).


CVE-2026-47053[5]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows low
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  Successful
| attacks require human interaction from a person other than the
| attacker. Successful attacks of this vulnerability can result in
| unauthorized creation, deletion or modification access to critical
| data or all Oracle VM VirtualBox accessible data and unauthorized
| ability to cause a partial denial of service (partial DOS) of Oracle
| VM VirtualBox. CVSS 3.1 Base Score 5.6 (Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L).


CVE-2026-47054[6]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows low
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  Successful
| attacks of this vulnerability can result in takeover of Oracle VM
| VirtualBox. Note: This vulnerability applies to Windows host only.
| CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).


CVE-2026-47055[7]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in  unauthorized update, insert or
| delete access to some of Oracle VM VirtualBox accessible data. CVSS
| 3.1 Base Score 3.2 (Integrity impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N).


CVE-2026-47062[8]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows low
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  Successful
| attacks of this vulnerability can result in unauthorized ability to
| cause a hang or frequently repeatable crash (complete DOS) of Oracle
| VM VirtualBox. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS
| Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60150[9]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows low
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  Successful
| attacks of this vulnerability can result in takeover of Oracle VM
| VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and
| Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).


CVE-2026-60155[10]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Difficult to exploit vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in takeover of Oracle VM VirtualBox.
| CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).


CVE-2026-60158[11]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Difficult to exploit vulnerability allows low
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in  unauthorized creation, deletion or
| modification access to critical data or all Oracle VM VirtualBox
| accessible data and unauthorized ability to cause a partial denial
| of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base
| Score 6.4 (Integrity and Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L).


CVE-2026-60159[12]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Difficult to exploit vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in takeover of Oracle VM VirtualBox.
| CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).


CVE-2026-60160[13]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in  unauthorized read access to a
| subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score
| 3.2 (Confidentiality impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).


CVE-2026-60161[14]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows
| unauthenticated attacker with logon to the infrastructure where
| Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.
| Successful attacks require human interaction from a person other
| than the attacker. Successful attacks of this vulnerability can
| result in unauthorized ability to cause a hang or frequently
| repeatable crash (complete DOS) of Oracle VM VirtualBox as well as
| unauthorized update, insert or delete access to some of Oracle VM
| VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and
| Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H).


CVE-2026-60162[15]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Difficult to exploit vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in  unauthorized access to critical
| data or complete access to all Oracle VM VirtualBox accessible data
| and unauthorized ability to cause a partial denial of service
| (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.1
| (Confidentiality and Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L).


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-47041
    https://www.cve.org/CVERecord?id=CVE-2026-47041
[1] https://security-tracker.debian.org/tracker/CVE-2026-47043
    https://www.cve.org/CVERecord?id=CVE-2026-47043
[2] https://security-tracker.debian.org/tracker/CVE-2026-47044
    https://www.cve.org/CVERecord?id=CVE-2026-47044
[3] https://security-tracker.debian.org/tracker/CVE-2026-47047
    https://www.cve.org/CVERecord?id=CVE-2026-47047
[4] https://security-tracker.debian.org/tracker/CVE-2026-47050
    https://www.cve.org/CVERecord?id=CVE-2026-47050
[5] https://security-tracker.debian.org/tracker/CVE-2026-47053
    https://www.cve.org/CVERecord?id=CVE-2026-47053
[6] https://security-tracker.debian.org/tracker/CVE-2026-47054
    https://www.cve.org/CVERecord?id=CVE-2026-47054
[7] https://security-tracker.debian.org/tracker/CVE-2026-47055
    https://www.cve.org/CVERecord?id=CVE-2026-47055
[8] https://security-tracker.debian.org/tracker/CVE-2026-47062
    https://www.cve.org/CVERecord?id=CVE-2026-47062
[9] https://security-tracker.debian.org/tracker/CVE-2026-60150
    https://www.cve.org/CVERecord?id=CVE-2026-60150
[10] https://security-tracker.debian.org/tracker/CVE-2026-60155
    https://www.cve.org/CVERecord?id=CVE-2026-60155
[11] https://security-tracker.debian.org/tracker/CVE-2026-60158
    https://www.cve.org/CVERecord?id=CVE-2026-60158
[12] https://security-tracker.debian.org/tracker/CVE-2026-60159
    https://www.cve.org/CVERecord?id=CVE-2026-60159
[13] https://security-tracker.debian.org/tracker/CVE-2026-60160
    https://www.cve.org/CVERecord?id=CVE-2026-60160
[14] https://security-tracker.debian.org/tracker/CVE-2026-60161
    https://www.cve.org/CVERecord?id=CVE-2026-60161
[15] https://security-tracker.debian.org/tracker/CVE-2026-60162
    https://www.cve.org/CVERecord?id=CVE-2026-60162

Regards,
Salvatore

Reply via email to