Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.833552
Category:SuSE Local Security Checks
Title:openSUSE: Security Advisory for virtualbox (openSUSE-SU-2023:0352-1)
Summary:The remote host is missing an update for the 'virtualbox'; package(s) announced via the openSUSE-SU-2023:0352-1 advisory.
Description:Summary:
The remote host is missing an update for the 'virtualbox'
package(s) announced via the openSUSE-SU-2023:0352-1 advisory.

Vulnerability Insight:
This update for virtualbox fixes the following issues:

- Version bump to VirtualBox 7.0.12 (released October 17 2023 by Oracle)

Fixes the following:

- CVE-2023-22098 (boo#1216363)

- CVE-2023-22099 (boo#1216364)

- CVE-2023-22100 (boo#1216365)

This is a maintenance release. The following items were fixed and/or added:

- VMM: Fixed using a debugger inside the guest under certain circumstances
(bugs #21413 and #21546)

- VMM: Fixed detection of VT-x being used by other hypervisors (bug #21867)

- VMM: Introduced additional improvements in Split Lock Detection feature
of recent Intel CPUs on Linux hosts (bug #20180)

- GUI: Fixed issue when the nested hardware virtualization setting was not
displayed in the VM details panel (bug #21707)

- GUI: Introduced NLS update for Croatian, Indonesian, Italian, Japanese,
Korean, Dutch and Turkish languages as well as added general
look-and-feel improvements

- Devices: Fixed black screen in Windows guests with multiple guest
screens when 3D is disabled (7.0.10 regression)

- Devices: Fixed PCI device identifiers for the VirtIO network interface
(bug #21516)

- Devices: Fixed VLAN support for the VirtIO network interface (bug #21778)

- Devices: Fixed loading saved states when a TPM is configured (7.0.10
regression, bug #21773)

- Networking: Fixed memory leaks in the VBoxIntNetSwitch process on macOS
(bug #21752)

- Networking: Fixed TCP connections with IP addresses ending on .2 when
the NAT network attachment is used (bug #21513)

- VRDP: Added general improvements

- VBoxManage: Added improvements for 'list usbfilters' command

- Unattended: Added kick start file support for Oracle Linux 8 and Oracle
Linux 9.

- Main: Added more Linux OS subtypes

- Host Services: Fixed Guest Properties service crash under rare
circumstance

- Linux Host and Guest: Fixed few 'field-spanning write' kernel warnings
(bugs #21410 and #21862)

- Linux Guest Additions: Added more fixes for RHEL 8.9 and 9.3 kernel

- Linux Guest Additions: Added more fixes for kernel 6.4

- Linux Guest Additions: Added initial support for OpenSUSE 15.5 kernel

- Linux Guest Additions: Added initial support for kernels 6.5 and 6.6

- Linux Guest Additions: Added version reporting for 'rcvboxadd
status-kernel' and 'rcvboxadd status-user' commands

- BIOS: Restored support for ISA SCSI HBAs in the BIOS (bug #21736)

- Convert to systemd-sysusers

- Fix problems with 6.5 kernels and shared folders. (boo#1215463).

Affected Software/OS:
'virtualbox' package(s) on openSUSE Leap 15.5.

Solution:
Please install the updated package(s).

CVSS Score:
6.5

CVSS Vector:
AV:L/AC:L/Au:M/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2023-22098
Oracle Advisory
https://www.oracle.com/security-alerts/cpuoct2023.html
Common Vulnerability Exposure (CVE) ID: CVE-2023-22099
Common Vulnerability Exposure (CVE) ID: CVE-2023-22100
CopyrightCopyright (C) 2024 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.