{"id":"MGASA-2022-0038","summary":"Updated virtualbox packages fix security vulnerability","details":"Updated virtualbox packages fix security vulnerability:\n\nVulnerability in the Oracle VM VirtualBoxp rior to 6.1.32 contains an \neasily exploitable vulnerability allows low privileged attacker with logon\nto the infrastructure where Oracle VM VirtualBox executes to compromise\nOracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, \nattacks may significantly impact additional products. Successful attacks\nof this vulnerability can result in unauthorized read access to a subset\nof Oracle VM VirtualBox accessible data (CVE-2022-21295).\n\nFor other fixes in this update, see the referenced changelog.\n","modified":"2026-04-16T04:43:27.835927536Z","published":"2022-01-26T19:51:18Z","upstream":["CVE-2022-21295"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2022-0038.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=29918"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujan2022.html#AppendixOVIR"},{"type":"WEB","url":"https://www.virtualbox.org/wiki/Changelog-6.1#v32"}],"affected":[{"package":{"name":"virtualbox","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/virtualbox?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.32-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2022-0038.json"}},{"package":{"name":"kmod-virtualbox","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/kmod-virtualbox?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.32-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2022-0038.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}