Source: virtualbox
Version: 7.2.14-dfsg-3
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for virtualbox.

CVE-2026-71113[0]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Easily exploitable vulnerability allows
| unauthenticated attacker with network access via RDP to compromise
| Oracle VM VirtualBox.  Successful attacks of this vulnerability can
| result in unauthorized ability to cause a hang or frequently
| repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1
| Base Score 7.5 (Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-71114[1]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in  unauthorized access to critical
| data or complete access to all Oracle VM VirtualBox accessible data.
| CVSS 3.1 Base Score 6.0 (Confidentiality impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).


CVE-2026-71115[2]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in  unauthorized access to critical
| data or complete access to all Oracle VM VirtualBox accessible data.
| CVSS 3.1 Base Score 6.0 (Confidentiality impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).


CVE-2026-71116[3]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Difficult to exploit vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in takeover of Oracle VM VirtualBox.
| CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).


CVE-2026-71125[4]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Easily exploitable vulnerability allows
| unauthenticated attacker with logon to the infrastructure where
| Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.
| Successful attacks require human interaction from a person other
| than the attacker. Successful attacks of this vulnerability can
| result in unauthorized ability to cause a hang or frequently
| repeatable crash (complete DOS) of Oracle VM VirtualBox as well as
| unauthorized update, insert or delete access to some of Oracle VM
| VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and
| Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H).


CVE-2026-71126[5]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Difficult to exploit vulnerability allows low
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in takeover of Oracle VM VirtualBox.
| CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).


CVE-2026-71127[6]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in unauthorized ability to cause a
| hang or frequently repeatable crash (complete DOS) of Oracle VM
| VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts).  CVSS
| Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).


CVE-2026-71128[7]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in unauthorized ability to cause a
| hang or frequently repeatable crash (complete DOS) of Oracle VM
| VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts).  CVSS
| Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).


CVE-2026-71129[8]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in takeover of Oracle VM VirtualBox.
| CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).


CVE-2026-71130[9]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Easily exploitable vulnerability allows
| unauthenticated attacker with network access via RDP to compromise
| Oracle VM VirtualBox.  Successful attacks of this vulnerability can
| result in  unauthorized access to critical data or complete access
| to all Oracle VM VirtualBox accessible data as well as  unauthorized
| update, insert or delete access to some of Oracle VM VirtualBox
| accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and
| Integrity impacts).  CVSS Vector:
| (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).


CVE-2026-71131[10]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Easily exploitable vulnerability allows
| unauthenticated attacker with logon to the infrastructure where
| Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.
| Successful attacks require human interaction from a person other
| than the attacker and while the vulnerability is in Oracle VM
| VirtualBox, attacks may significantly impact additional products
| (scope change). Successful attacks of this vulnerability can result
| in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.6
| (Confidentiality, Integrity and Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


CVE-2026-71132[11]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Difficult to exploit vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in  unauthorized access to critical
| data or complete access to all Oracle VM VirtualBox accessible data.
| CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N).


CVE-2026-71134[12]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in  unauthorized update, insert or
| delete access to some of Oracle VM VirtualBox accessible data as
| well as  unauthorized read access to a subset of Oracle VM
| VirtualBox accessible data and unauthorized ability to cause a
| partial denial of service (partial DOS) of Oracle VM VirtualBox.
| CVSS 3.1 Base Score 5.7 (Confidentiality, Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L).


CVE-2026-71135[13]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in unauthorized ability to cause a
| hang or frequently repeatable crash (complete DOS) of Oracle VM
| VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts).  CVSS
| Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).


CVE-2026-71136[14]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in unauthorized ability to cause a
| hang or frequently repeatable crash (complete DOS) of Oracle VM
| VirtualBox as well as  unauthorized update, insert or delete access
| to some of Oracle VM VirtualBox accessible data and  unauthorized
| read access to a subset of Oracle VM VirtualBox accessible data.
| CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).


CVE-2026-71137[15]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in unauthorized ability to cause a
| hang or frequently repeatable crash (complete DOS) of Oracle VM
| VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts).  CVSS
| Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).


CVE-2026-71138[16]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in unauthorized ability to cause a
| hang or frequently repeatable crash (complete DOS) of Oracle VM
| VirtualBox as well as  unauthorized update, insert or delete access
| to some of Oracle VM VirtualBox accessible data and  unauthorized
| read access to a subset of Oracle VM VirtualBox accessible data.
| CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).


CVE-2026-71139[17]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  Successful
| attacks of this vulnerability can result in unauthorized ability to
| cause a hang or frequently repeatable crash (complete DOS) of Oracle
| VM VirtualBox. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS
| Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-71140[18]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  Successful
| attacks of this vulnerability can result in  unauthorized update,
| insert or delete access to some of Oracle VM VirtualBox accessible
| data as well as  unauthorized read access to a subset of Oracle VM
| VirtualBox accessible data. CVSS 3.1 Base Score 3.4 (Confidentiality
| and Integrity impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).


CVE-2026-71141[19]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Easily exploitable vulnerability allows
| unauthenticated attacker with logon to the infrastructure where
| Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.
| Successful attacks require human interaction from a person other
| than the attacker and while the vulnerability is in Oracle VM
| VirtualBox, attacks may significantly impact additional products
| (scope change). Successful attacks of this vulnerability can result
| in  unauthorized creation, deletion or modification access to
| critical data or all Oracle VM VirtualBox accessible data as well as
| unauthorized read access to a subset of Oracle VM VirtualBox
| accessible data and unauthorized ability to cause a partial denial
| of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base
| Score 7.7 (Confidentiality, Integrity and Availability impacts).
| CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L).


CVE-2026-71151[20]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.14. Difficult to exploit vulnerability allows low
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in  unauthorized access to critical
| data or complete access to all Oracle VM VirtualBox accessible data.
| CVSS 3.1 Base Score 5.6 (Confidentiality impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-71113
    https://www.cve.org/CVERecord?id=CVE-2026-71113
[1] https://security-tracker.debian.org/tracker/CVE-2026-71114
    https://www.cve.org/CVERecord?id=CVE-2026-71114
[2] https://security-tracker.debian.org/tracker/CVE-2026-71115
    https://www.cve.org/CVERecord?id=CVE-2026-71115
[3] https://security-tracker.debian.org/tracker/CVE-2026-71116
    https://www.cve.org/CVERecord?id=CVE-2026-71116
[4] https://security-tracker.debian.org/tracker/CVE-2026-71125
    https://www.cve.org/CVERecord?id=CVE-2026-71125
[5] https://security-tracker.debian.org/tracker/CVE-2026-71126
    https://www.cve.org/CVERecord?id=CVE-2026-71126
[6] https://security-tracker.debian.org/tracker/CVE-2026-71127
    https://www.cve.org/CVERecord?id=CVE-2026-71127
[7] https://security-tracker.debian.org/tracker/CVE-2026-71128
    https://www.cve.org/CVERecord?id=CVE-2026-71128
[8] https://security-tracker.debian.org/tracker/CVE-2026-71129
    https://www.cve.org/CVERecord?id=CVE-2026-71129
[9] https://security-tracker.debian.org/tracker/CVE-2026-71130
    https://www.cve.org/CVERecord?id=CVE-2026-71130
[10] https://security-tracker.debian.org/tracker/CVE-2026-71131
    https://www.cve.org/CVERecord?id=CVE-2026-71131
[11] https://security-tracker.debian.org/tracker/CVE-2026-71132
    https://www.cve.org/CVERecord?id=CVE-2026-71132
[12] https://security-tracker.debian.org/tracker/CVE-2026-71134
    https://www.cve.org/CVERecord?id=CVE-2026-71134
[13] https://security-tracker.debian.org/tracker/CVE-2026-71135
    https://www.cve.org/CVERecord?id=CVE-2026-71135
[14] https://security-tracker.debian.org/tracker/CVE-2026-71136
    https://www.cve.org/CVERecord?id=CVE-2026-71136
[15] https://security-tracker.debian.org/tracker/CVE-2026-71137
    https://www.cve.org/CVERecord?id=CVE-2026-71137
[16] https://security-tracker.debian.org/tracker/CVE-2026-71138
    https://www.cve.org/CVERecord?id=CVE-2026-71138
[17] https://security-tracker.debian.org/tracker/CVE-2026-71139
    https://www.cve.org/CVERecord?id=CVE-2026-71139
[18] https://security-tracker.debian.org/tracker/CVE-2026-71140
    https://www.cve.org/CVERecord?id=CVE-2026-71140
[19] https://security-tracker.debian.org/tracker/CVE-2026-71141
    https://www.cve.org/CVERecord?id=CVE-2026-71141
[20] https://security-tracker.debian.org/tracker/CVE-2026-71151
    https://www.cve.org/CVERecord?id=CVE-2026-71151

Regards,
Salvatore

Reply via email to