{"id":"openSUSE-SU-2022:10067-1","summary":"Security update for virtualbox","details":"This update for virtualbox fixes the following issues:\n\n- Save and restore FPU status during interrupt. (boo#1199803)\n\n- Update support of building with Python\n\n- Replace SDL-devel BuildRequires with pkgconfig(sdl): allow to use\n  sdl12_compat as an alternative.\n\nVersion bump to 6.1.36 released by Oracle July 19 2022\n\nThis is a maintenance release. The following items were fixed and/or added:\n\n- VMM: Fixed possible Linux guest kernel crash when configuring Speculative Store Bypass for a single vCPU VM\n- GUI: In the storage page of the virtual machine settings dialog, fixed a bug which disrupted mouse interaction with the native file selector on KDE\n- NAT: Prevent issue when host resolver incorrectly returned NXDOMAIN for unsupported queries (bug #20977)\n- Audio: General improvements in saved state area\n- Recording: Various fixes for settings handling\n- VGA: Performance improvements for screen updates when VBE banking is used\n- USB: Fixed rare crashes when detaching a USB device\n- ATA: Fixed NT4 guests taking a minute to eject CDs\n- vboximg-mount: Fixed broken write support (bug #20896)\n- SDK: Fixed Python bindings incorrectly trying to convert arbitrary byte data into unicode objects with Python 3, causing exceptions (bug #19740)\n- API: Fixed an issue when virtual USB mass storage devices or virtual USB DVD drives are added while the VM is not running are by default not marked as hot-pluggable\n- API: Initial support for Python 3.10\n- API: Solaris OS types cleanup\n- Linux and Solaris hosts: Allow to mount shared folder if it is represented as a symlink on a host side (bug #17491)\n- Linux Host and Guest drivers: Introduced initial support for kernels 5.18, 5.19 and RHEL 9.1 (bugs #20914, #20941)\n- Linux Host and Guest drivers: Better support for kernels built with clang compiler (bugs #20425 and #20998)\n- Solaris Guest Additions: General improvements in installer area\n- Solaris Guest Additions: Fixed guest screen resize in VMSVGA graphics configuration\n- Linux and Solaris Guest Additions: Fixed multi-screen handling in VBoxVGA and VBoxSVGA graphics configuration\n- Linux and Solaris Guest Additions: Added support for setting primary screen via VBoxManage\n- Linux and Solaris Guest Additions: Fixed X11 resources leak when resizing guest screens\n- Linux and Solaris Guest Additions: Fixed file descriptor leak when starting a process using guest control (bug #20902)\n- Linux and Solaris Guest Additions: Fixed guest control executing processes as root\n- Linux Guest Additions: Improved guests booting time by preventing kernel modules from being rebuilt when it is not necessary (bug #20502)\n- Windows Guest Additions: Fixed VBoxTray crash on startup in NT4 guests on rare circumstances\n\n- Fixes CVE-2022-21571,CVE-2022-21554 - boo#1201720\n\nVersion bump to 6.1.34 (released March 22 2022) by Oracle\n\n- This is a maintenance release. The following items were fixed and/or added:\n- VMM: Fix instruction emulation for 'cmpxchg16b'\n- GUI: Improved GUI behavior on macOS Big Sur and later when kernel extensions are not loaded\n- EHCI: Addressed an issue with handling short packets (bug #20726)\n- Storage: Fixed a potential hang during disk I/O when the host I/O cache is disabled (bug #20875)\n- NVMe: Fixed loading saved state when nothing is attached to it (bug #20791)\n- DevPcBios: Addressed an issue which resulted in rejecting the detected LCHS geometry when the head count was above 16\n- virtio-scsi: Improvements\n- E1000: Improve descriptor handling\n- VBoxManage: Fixed handling of command line arguments with incomplete quotes (bug #20740)\n- VBoxManage: Improved 'natnetwork list' output\n- VBoxManage: NATNetwork: Provide an option (--ipv6-prefix) to set IPv6 prefix\n- VBoxManage: NATNetwork: Provide an option (--ipv6-default) to advertise default IPv6 route (bug #20714)\n- VBoxManage: Fix documentation of 'usbdevsource add' (bug #20849)\n- Networking: General improvements in IPv4 and IPv6 area (bug #20714)\n- OVF Import: Allow users to specify a different storage controller and/or controller port for hard disks when importing a VM\n- Unattended install: Improvements\n- Shared Clipboard: Improved HTML clipboard handling for Windows host\n- Linux host and guest: Introduced initial support for kernel 5.17\n- Solaris package: Fixes for API access from Python\n- Solaris IPS package: Suppress dependency on libpython2.7.so.*\n- Linux host and guest: Fixes for Linux kernel 5.14\n- Linux Guest Additions: Fixed guest screen resize for older guests which are running libXrandr older than version 1.4\n- Linux Guest Additions: Introduced initial support for RHEL 8.6 kernels (bug #20877)\n- Windows guest: Make driver install smarter\n- Solaris guest: Addressed an issue which prevented VBox GAs 6.1.30 or 6.1.32 from being removed in Solaris 10 guests (bug #20780)\n- EFI: Fixed booting from FreeBSD ISO images (bug #19910)\n- Fixes CVE-2022-21465 (boo#1198676), CVE-2022-21471 (boo#1198677), CVE-2022-21491 (boo#1198680), CVE-2022-21487 (boo#1198678), and CVE-2022-21488 (boo#1198679).\n- package virtualbox-websrv needs sysvinit-tools (boo#1198703)\n","modified":"2026-02-04T03:46:32.448972Z","published":"2022-07-27T08:43:51Z","related":["CVE-2022-21465","CVE-2022-21471","CVE-2022-21487","CVE-2022-21488","CVE-2022-21491","CVE-2022-21554","CVE-2022-21571"],"upstream":["CVE-2022-21465","CVE-2022-21471","CVE-2022-21487","CVE-2022-21488","CVE-2022-21491","CVE-2022-21554","CVE-2022-21571"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MUBDJCH5DQPJ7XOEJZUNCPQIWVNBR4ND/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198676"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198677"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198678"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198679"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198680"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198703"},{"type":"REPORT","url":"https://bugzilla.suse.com/1199803"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201720"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-21465"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-21471"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-21487"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-21488"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-21491"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-21554"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-21571"}],"affected":[{"package":{"name":"virtualbox","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/virtualbox&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.36-lp154.2.7.1"}]}],"ecosystem_specific":{"binaries":[{"virtualbox-qt":"6.1.36-lp154.2.7.1","virtualbox-vnc":"6.1.36-lp154.2.7.1","virtualbox-websrv":"6.1.36-lp154.2.7.1","virtualbox":"6.1.36-lp154.2.7.1","virtualbox-devel":"6.1.36-lp154.2.7.1","virtualbox-guest-desktop-icons":"6.1.36-lp154.2.7.1","virtualbox-guest-source":"6.1.36-lp154.2.7.1","virtualbox-guest-tools":"6.1.36-lp154.2.7.1","virtualbox-guest-x11":"6.1.36-lp154.2.7.1","virtualbox-host-source":"6.1.36-lp154.2.7.1","python3-virtualbox":"6.1.36-lp154.2.7.1","virtualbox-kmp-default":"6.1.36_k5.14.21_150400.24.11-lp154.2.7.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10067-1.json"}},{"package":{"name":"virtualbox-kmp","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/virtualbox-kmp&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.36-lp154.2.7.1"}]}],"ecosystem_specific":{"binaries":[{"virtualbox-guest-desktop-icons":"6.1.36-lp154.2.7.1","virtualbox-host-source":"6.1.36-lp154.2.7.1","virtualbox-kmp-default":"6.1.36_k5.14.21_150400.24.11-lp154.2.7.1","virtualbox-websrv":"6.1.36-lp154.2.7.1","virtualbox-guest-source":"6.1.36-lp154.2.7.1","virtualbox-guest-tools":"6.1.36-lp154.2.7.1","virtualbox-guest-x11":"6.1.36-lp154.2.7.1","virtualbox-qt":"6.1.36-lp154.2.7.1","virtualbox-vnc":"6.1.36-lp154.2.7.1","virtualbox":"6.1.36-lp154.2.7.1","python3-virtualbox":"6.1.36-lp154.2.7.1","virtualbox-devel":"6.1.36-lp154.2.7.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10067-1.json"}}],"schema_version":"1.7.3"}