Bug 1198676 (CVE-2022-21465) - VUL-0: CVE-2022-21465: virtualbox: Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox
Summary: VUL-0: CVE-2022-21465: virtualbox: Easily exploitable vulnerability allows hi...
Status: RESOLVED FIXED
Alias: CVE-2022-21465
Product: openSUSE Distribution
Classification: openSUSE
Component: Basesystem (show other bugs)
Version: Leap 15.3
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Larry Finger
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/329571/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-04-20 07:42 UTC by Alexander Bergmann
Modified: 2022-07-27 13:16 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2022-04-20 07:42:09 UTC
CVE-2022-21465

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization
(component: Core). The supported version that is affected is Prior to 6.1.34.
Easily exploitable vulnerability allows high privileged attacker with logon to
the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM
VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may
significantly impact additional products (scope change). Successful attacks of
this vulnerability can result in unauthorized ability to cause a hang or
frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as
unauthorized update, insert or delete access to some of Oracle VM VirtualBox
accessible data. CVSS 3.1 Base Score 6.7 (Integrity and Availability impacts).
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H).

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-21465
https://www.oracle.com/security-alerts/cpuapr2022.html#CVE-2022-21465
https://www.oracle.com/security-alerts/cpuapr2022.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21465
Comment 1 OBSbugzilla Bot 2022-05-05 22:40:04 UTC
This is an autogenerated message for OBS integration:
This bug (1198676) was mentioned in
https://build.opensuse.org/request/show/975266 15.3 / virtualbox
Comment 2 Larry Finger 2022-05-06 01:29:05 UTC
VB version 6.1.34 fixes this issue and has been submitted to TW, Leap 15.4, Leap 15.3, and Leap 15.2,
Comment 3 OBSbugzilla Bot 2022-05-06 02:40:09 UTC
This is an autogenerated message for OBS integration:
This bug (1198676) was mentioned in
https://build.opensuse.org/request/show/975277 15.2 / virtualbox
Comment 4 Swamp Workflow Management 2022-05-18 13:19:03 UTC
openSUSE-SU-2022:0135-1: An update that fixes 32 vulnerabilities is now available.

Category: security (important)
Bug References: 1064976,1064978,1069412,1099260,1099263,1102912,1121426,1121428,1184522,1192869,1198676,1198677,1198678,1198679,1198680,1198703,951562,970662,970663,991940
CVE References: CVE-2011-5325,CVE-2015-9261,CVE-2016-2147,CVE-2016-2148,CVE-2016-6301,CVE-2017-15873,CVE-2017-15874,CVE-2017-16544,CVE-2018-1000500,CVE-2018-1000517,CVE-2018-20679,CVE-2019-5747,CVE-2021-28831,CVE-2021-42373,CVE-2021-42374,CVE-2021-42375,CVE-2021-42376,CVE-2021-42377,CVE-2021-42378,CVE-2021-42379,CVE-2021-42380,CVE-2021-42381,CVE-2021-42382,CVE-2021-42383,CVE-2021-42384,CVE-2021-42385,CVE-2021-42386,CVE-2022-21465,CVE-2022-21471,CVE-2022-21487,CVE-2022-21488,CVE-2022-21491
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    busybox-1.34.1-4.9.1, virtualbox-6.1.34-lp153.2.27.2, virtualbox-kmp-6.1.34-lp153.2.27.1
Comment 5 OBSbugzilla Bot 2022-06-09 06:40:03 UTC
This is an autogenerated message for OBS integration:
This bug (1198676) was mentioned in
https://build.opensuse.org/request/show/981407 15.4 / virtualbox
Comment 6 OBSbugzilla Bot 2022-06-23 00:40:02 UTC
This is an autogenerated message for OBS integration:
This bug (1198676) was mentioned in
https://build.opensuse.org/request/show/984619 15.4 / virtualbox
Comment 7 OBSbugzilla Bot 2022-07-22 18:40:05 UTC
This is an autogenerated message for OBS integration:
This bug (1198676) was mentioned in
https://build.opensuse.org/request/show/990708 15.4 / virtualbox
Comment 8 Swamp Workflow Management 2022-07-27 13:16:45 UTC
openSUSE-SU-2022:10067-1: An update that solves 7 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1198676,1198677,1198678,1198679,1198680,1198703,1199803,1201720
CVE References: CVE-2022-21465,CVE-2022-21471,CVE-2022-21487,CVE-2022-21488,CVE-2022-21491,CVE-2022-21554,CVE-2022-21571
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    virtualbox-6.1.36-lp154.2.7.1, virtualbox-kmp-6.1.36-lp154.2.7.1