Bug 1198680 (CVE-2022-21491)

Summary: VUL-0: CVE-2022-21491: virtualbox: Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox
Product: [openSUSE] openSUSE Distribution Reporter: Alexander Bergmann <abergmann>
Component: BasesystemAssignee: Larry Finger <Larry.Finger>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Major    
Priority: P3 - Medium    
Version: Leap 15.3   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/329597/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Alexander Bergmann 2022-04-20 07:42:20 UTC
CVE-2022-21491

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization
(component: Core). The supported version that is affected is Prior to 6.1.34.
Easily exploitable vulnerability allows low privileged attacker with logon to
the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM
VirtualBox. Successful attacks of this vulnerability can result in takeover of
Oracle VM VirtualBox. Note: This vulnerability applies to Windows systems only.
CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-21491
https://www.oracle.com/security-alerts/cpuapr2022.html#CVE-2022-21491
https://www.oracle.com/security-alerts/cpuapr2022.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21491
Comment 1 OBSbugzilla Bot 2022-05-05 22:40:11 UTC
This is an autogenerated message for OBS integration:
This bug (1198680) was mentioned in
https://build.opensuse.org/request/show/975266 15.3 / virtualbox
Comment 2 Larry Finger 2022-05-06 01:31:47 UTC
VB version 6.1.34 fixes this issue and has been submitted to TW, Leap 15.4, Leap 15.3, and Leap 15.2,
Comment 3 OBSbugzilla Bot 2022-05-06 02:40:15 UTC
This is an autogenerated message for OBS integration:
This bug (1198680) was mentioned in
https://build.opensuse.org/request/show/975277 15.2 / virtualbox
Comment 4 Swamp Workflow Management 2022-05-18 13:19:20 UTC
openSUSE-SU-2022:0135-1: An update that fixes 32 vulnerabilities is now available.

Category: security (important)
Bug References: 1064976,1064978,1069412,1099260,1099263,1102912,1121426,1121428,1184522,1192869,1198676,1198677,1198678,1198679,1198680,1198703,951562,970662,970663,991940
CVE References: CVE-2011-5325,CVE-2015-9261,CVE-2016-2147,CVE-2016-2148,CVE-2016-6301,CVE-2017-15873,CVE-2017-15874,CVE-2017-16544,CVE-2018-1000500,CVE-2018-1000517,CVE-2018-20679,CVE-2019-5747,CVE-2021-28831,CVE-2021-42373,CVE-2021-42374,CVE-2021-42375,CVE-2021-42376,CVE-2021-42377,CVE-2021-42378,CVE-2021-42379,CVE-2021-42380,CVE-2021-42381,CVE-2021-42382,CVE-2021-42383,CVE-2021-42384,CVE-2021-42385,CVE-2021-42386,CVE-2022-21465,CVE-2022-21471,CVE-2022-21487,CVE-2022-21488,CVE-2022-21491
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    busybox-1.34.1-4.9.1, virtualbox-6.1.34-lp153.2.27.2, virtualbox-kmp-6.1.34-lp153.2.27.1
Comment 5 OBSbugzilla Bot 2022-06-09 06:40:10 UTC
This is an autogenerated message for OBS integration:
This bug (1198680) was mentioned in
https://build.opensuse.org/request/show/981407 15.4 / virtualbox
Comment 6 OBSbugzilla Bot 2022-06-23 00:40:08 UTC
This is an autogenerated message for OBS integration:
This bug (1198680) was mentioned in
https://build.opensuse.org/request/show/984619 15.4 / virtualbox
Comment 7 OBSbugzilla Bot 2022-07-22 18:40:11 UTC
This is an autogenerated message for OBS integration:
This bug (1198680) was mentioned in
https://build.opensuse.org/request/show/990708 15.4 / virtualbox
Comment 8 Swamp Workflow Management 2022-07-27 13:17:01 UTC
openSUSE-SU-2022:10067-1: An update that solves 7 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1198676,1198677,1198678,1198679,1198680,1198703,1199803,1201720
CVE References: CVE-2022-21465,CVE-2022-21471,CVE-2022-21487,CVE-2022-21488,CVE-2022-21491,CVE-2022-21554,CVE-2022-21571
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    virtualbox-6.1.36-lp154.2.7.1, virtualbox-kmp-6.1.36-lp154.2.7.1