| Summary: | virtualbox new security issues CVE-2022-21554 and CVE-2022-21571 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | critical | ||
| Priority: | Normal | CC: | andrewsfarm, davidwhodgins, fri, ottoleipala1, sysadmin-bugs, tmb |
| Version: | 8 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8-64-OK, MGA8-32-OK | ||
| Source RPM: | virtualbox-6.1.34-10.mga9.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2022-07-20 15:42:38 CEST
David Walser
2022-07-20 15:42:50 CEST
Status comment:
(none) =>
Fixed upstream in 6.1.36 SRPMS: virtualbox-6.1.36-1.mga8.src.rpm kmod-virtualbox-6.1.36-1.mga8.src.rpm i586: virtualbox-6.1.36-1.mga8.i586.rpm virtualbox-guest-additions-6.1.36-1.mga8.i586.rpm x86_64: dkms-virtualbox-6.1.36-1.mga8.x86_64.rpm python-virtualbox-6.1.36-1.mga8.x86_64.rpm virtualbox-6.1.36-1.mga8.x86_64.rpm virtualbox-devel-6.1.36-1.mga8.x86_64.rpm virtualbox-guest-additions-6.1.36-1.mga8.x86_64.rpm virtualbox-kernel-5.15.55-desktop-2.mga8-6.1.36-1.mga8.x86_64.rpm virtualbox-kernel-5.15.55-server-2.mga8-6.1.36-1.mga8.x86_64.rpm virtualbox-kernel-desktop-latest-6.1.36-1.mga8.x86_64.rpm virtualbox-kernel-server-latest-6.1.36-1.mga8.x86_64.rpm And for those using backports kernels, there are kmods: SRPMS: kmod-virtualbox-6.1.36-2.mga8.src.rpm x86_64: dkms-virtualbox-6.1.36-1.mga8.x86_64.rpm virtualbox-kernel-5.18.12-desktop-1.mga8-6.1.36-2.mga8.x86_64.rpm virtualbox-kernel-5.18.12-server-1.mga8-6.1.36-2.mga8.x86_64.rpm virtualbox-kernel-desktop-latest-6.1.36-2.mga8.x86_64.rpm virtualbox-kernel-server-latest-6.1.36-2.mga8.x86_64.rpm Version:
Cauldron =>
8
David Walser
2022-07-21 14:53:58 CEST
Status comment:
Fixed upstream in 6.1.36 =>
(none)
David Walser
2022-07-21 14:54:38 CEST
CC:
(none) =>
tmb Seems to working ok with my Debian Sid guest system kernel 5.18. CC:
(none) =>
ottoleipala1 OK at my usual test/workstation; nvidia-current, Plasma Testing with backport kernel 5.18.12-desktop-1.mga8 Hardware: My workstation "svarten": Mainboard: Sabertooth P67, CPU: i7-3770, RAM 16G, GM107 [GeForce GTX 750] using nvidia-current; GeForce 635 series and later, 4k display. Updated VirtualBox packages: virtualbox-6.1.36-1.mga8.x86_64.rpm dkms-virtualbox-6.1.36-1.mga8.x86_64.rpm virtualbox-kernel-5.18.12-desktop-1.mga8-6.1.36-2.mga8.x86_64.rpm virtualbox-kernel-desktop-latest-6.1.36-2.mga8.x86_64.rpm rebooted dkms status is OK Fetched extpack manyally and installed it $ sudo VBoxManage extpack install --replace Oracle_VM_VirtualBox_Extension_Pack-6.1.36a-152435.vbox-extpack ___Performed the tests I use to: Guest 1: MSW7pro 64 bit: In the guest VirtualBox window menu: Devices > insert guest extension disk, let it fetch and insert in drive. Opened that disk and launched VBoxWindowsAdditions.exe, and rebooted. Dynamically resizing guest window by mouse Shared clipboard, bidirectional Shared folders bidirectional read/write copying, and readonly works correctly. Drag a file from host Dolphin to guest Explorer USB2: compactflash adapter with card, and Conitec Galep-5 chip programmer Sound, Internet, performance: playing video in Firefox Windows update (antivirus definitions) Guest 2: BOINC LHC@home "ATLAS simulation 2.00" VirtualBox 64 bit VM @5CPU Works. CC:
(none) =>
fri No regressions noticed with m8 i586 and x86_64 guests on a x86_64 host. CC:
(none) =>
davidwhodgins OK also with kernel 5.15.55-desktop-2.mga8, same system; Since Comment 3: 1) $ sudo urpmi virtualbox-kernel-5.15.55-desktop-2.mga8-6.1.36-1.mga8 2) reboot with kernel 5.15.55 (installed and tested days earlier) 3) Performed all tests again (except windows update) Working OK on my Probook 6550b, with a Windows 7 guest. Win7 guest additions seemed much more elaborate than usual, and took a long time to install, but were eventually successful. CC:
(none) =>
andrewsfarm
Thomas Backlund
2022-07-25 10:49:05 CEST
CC:
(none) =>
sysadmin-bugs An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2022-0265.html Status:
NEW =>
RESOLVED |