Source: virtualbox Version: 7.2.14-dfsg-3 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for virtualbox. CVE-2026-71113[0]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Easily exploitable vulnerability allows | unauthenticated attacker with network access via RDP to compromise | Oracle VM VirtualBox. Successful attacks of this vulnerability can | result in unauthorized ability to cause a hang or frequently | repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 | Base Score 7.5 (Availability impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). CVE-2026-71114[1]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Easily exploitable vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in unauthorized access to critical | data or complete access to all Oracle VM VirtualBox accessible data. | CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N). CVE-2026-71115[2]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Easily exploitable vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in unauthorized access to critical | data or complete access to all Oracle VM VirtualBox accessible data. | CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N). CVE-2026-71116[3]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Difficult to exploit vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in takeover of Oracle VM VirtualBox. | CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability | impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H). CVE-2026-71125[4]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Easily exploitable vulnerability allows | unauthenticated attacker with logon to the infrastructure where | Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. | Successful attacks require human interaction from a person other | than the attacker. Successful attacks of this vulnerability can | result in unauthorized ability to cause a hang or frequently | repeatable crash (complete DOS) of Oracle VM VirtualBox as well as | unauthorized update, insert or delete access to some of Oracle VM | VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and | Availability impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H). CVE-2026-71126[5]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Difficult to exploit vulnerability allows low | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in takeover of Oracle VM VirtualBox. | CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability | impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H). CVE-2026-71127[6]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Easily exploitable vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in unauthorized ability to cause a | hang or frequently repeatable crash (complete DOS) of Oracle VM | VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS | Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H). CVE-2026-71128[7]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Easily exploitable vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in unauthorized ability to cause a | hang or frequently repeatable crash (complete DOS) of Oracle VM | VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS | Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H). CVE-2026-71129[8]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Easily exploitable vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in takeover of Oracle VM VirtualBox. | CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability | impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). CVE-2026-71130[9]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Easily exploitable vulnerability allows | unauthenticated attacker with network access via RDP to compromise | Oracle VM VirtualBox. Successful attacks of this vulnerability can | result in unauthorized access to critical data or complete access | to all Oracle VM VirtualBox accessible data as well as unauthorized | update, insert or delete access to some of Oracle VM VirtualBox | accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and | Integrity impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). CVE-2026-71131[10]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Easily exploitable vulnerability allows | unauthenticated attacker with logon to the infrastructure where | Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. | Successful attacks require human interaction from a person other | than the attacker and while the vulnerability is in Oracle VM | VirtualBox, attacks may significantly impact additional products | (scope change). Successful attacks of this vulnerability can result | in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.6 | (Confidentiality, Integrity and Availability impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). CVE-2026-71132[11]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Difficult to exploit vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in unauthorized access to critical | data or complete access to all Oracle VM VirtualBox accessible data. | CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N). CVE-2026-71134[12]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Easily exploitable vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in unauthorized update, insert or | delete access to some of Oracle VM VirtualBox accessible data as | well as unauthorized read access to a subset of Oracle VM | VirtualBox accessible data and unauthorized ability to cause a | partial denial of service (partial DOS) of Oracle VM VirtualBox. | CVSS 3.1 Base Score 5.7 (Confidentiality, Integrity and Availability | impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L). CVE-2026-71135[13]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Easily exploitable vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in unauthorized ability to cause a | hang or frequently repeatable crash (complete DOS) of Oracle VM | VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS | Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H). CVE-2026-71136[14]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Easily exploitable vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in unauthorized ability to cause a | hang or frequently repeatable crash (complete DOS) of Oracle VM | VirtualBox as well as unauthorized update, insert or delete access | to some of Oracle VM VirtualBox accessible data and unauthorized | read access to a subset of Oracle VM VirtualBox accessible data. | CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability | impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H). CVE-2026-71137[15]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Easily exploitable vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in unauthorized ability to cause a | hang or frequently repeatable crash (complete DOS) of Oracle VM | VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS | Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H). CVE-2026-71138[16]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Easily exploitable vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in unauthorized ability to cause a | hang or frequently repeatable crash (complete DOS) of Oracle VM | VirtualBox as well as unauthorized update, insert or delete access | to some of Oracle VM VirtualBox accessible data and unauthorized | read access to a subset of Oracle VM VirtualBox accessible data. | CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability | impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H). CVE-2026-71139[17]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Easily exploitable vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. Successful | attacks of this vulnerability can result in unauthorized ability to | cause a hang or frequently repeatable crash (complete DOS) of Oracle | VM VirtualBox. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS | Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). CVE-2026-71140[18]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Easily exploitable vulnerability allows high | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. Successful | attacks of this vulnerability can result in unauthorized update, | insert or delete access to some of Oracle VM VirtualBox accessible | data as well as unauthorized read access to a subset of Oracle VM | VirtualBox accessible data. CVSS 3.1 Base Score 3.4 (Confidentiality | and Integrity impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N). CVE-2026-71141[19]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Easily exploitable vulnerability allows | unauthenticated attacker with logon to the infrastructure where | Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. | Successful attacks require human interaction from a person other | than the attacker and while the vulnerability is in Oracle VM | VirtualBox, attacks may significantly impact additional products | (scope change). Successful attacks of this vulnerability can result | in unauthorized creation, deletion or modification access to | critical data or all Oracle VM VirtualBox accessible data as well as | unauthorized read access to a subset of Oracle VM VirtualBox | accessible data and unauthorized ability to cause a partial denial | of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base | Score 7.7 (Confidentiality, Integrity and Availability impacts). | CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L). CVE-2026-71151[20]: | Vulnerability in the Oracle VM VirtualBox product of Oracle | Virtualization (component: Core). The supported version that is | affected is 7.2.14. Difficult to exploit vulnerability allows low | privileged attacker with logon to the infrastructure where Oracle VM | VirtualBox executes to compromise Oracle VM VirtualBox. While the | vulnerability is in Oracle VM VirtualBox, attacks may significantly | impact additional products (scope change). Successful attacks of | this vulnerability can result in unauthorized access to critical | data or complete access to all Oracle VM VirtualBox accessible data. | CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: | (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N). If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-71113 https://www.cve.org/CVERecord?id=CVE-2026-71113 [1] https://security-tracker.debian.org/tracker/CVE-2026-71114 https://www.cve.org/CVERecord?id=CVE-2026-71114 [2] https://security-tracker.debian.org/tracker/CVE-2026-71115 https://www.cve.org/CVERecord?id=CVE-2026-71115 [3] https://security-tracker.debian.org/tracker/CVE-2026-71116 https://www.cve.org/CVERecord?id=CVE-2026-71116 [4] https://security-tracker.debian.org/tracker/CVE-2026-71125 https://www.cve.org/CVERecord?id=CVE-2026-71125 [5] https://security-tracker.debian.org/tracker/CVE-2026-71126 https://www.cve.org/CVERecord?id=CVE-2026-71126 [6] https://security-tracker.debian.org/tracker/CVE-2026-71127 https://www.cve.org/CVERecord?id=CVE-2026-71127 [7] https://security-tracker.debian.org/tracker/CVE-2026-71128 https://www.cve.org/CVERecord?id=CVE-2026-71128 [8] https://security-tracker.debian.org/tracker/CVE-2026-71129 https://www.cve.org/CVERecord?id=CVE-2026-71129 [9] https://security-tracker.debian.org/tracker/CVE-2026-71130 https://www.cve.org/CVERecord?id=CVE-2026-71130 [10] https://security-tracker.debian.org/tracker/CVE-2026-71131 https://www.cve.org/CVERecord?id=CVE-2026-71131 [11] https://security-tracker.debian.org/tracker/CVE-2026-71132 https://www.cve.org/CVERecord?id=CVE-2026-71132 [12] https://security-tracker.debian.org/tracker/CVE-2026-71134 https://www.cve.org/CVERecord?id=CVE-2026-71134 [13] https://security-tracker.debian.org/tracker/CVE-2026-71135 https://www.cve.org/CVERecord?id=CVE-2026-71135 [14] https://security-tracker.debian.org/tracker/CVE-2026-71136 https://www.cve.org/CVERecord?id=CVE-2026-71136 [15] https://security-tracker.debian.org/tracker/CVE-2026-71137 https://www.cve.org/CVERecord?id=CVE-2026-71137 [16] https://security-tracker.debian.org/tracker/CVE-2026-71138 https://www.cve.org/CVERecord?id=CVE-2026-71138 [17] https://security-tracker.debian.org/tracker/CVE-2026-71139 https://www.cve.org/CVERecord?id=CVE-2026-71139 [18] https://security-tracker.debian.org/tracker/CVE-2026-71140 https://www.cve.org/CVERecord?id=CVE-2026-71140 [19] https://security-tracker.debian.org/tracker/CVE-2026-71141 https://www.cve.org/CVERecord?id=CVE-2026-71141 [20] https://security-tracker.debian.org/tracker/CVE-2026-71151 https://www.cve.org/CVERecord?id=CVE-2026-71151 Regards, Salvatore

