UBUNTU-CVE-2021-25319

Source
https://ubuntu.com/security/CVE-2021-25319
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-25319.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2021-25319
Upstream
Published
2021-05-05T09:15:00Z
Modified
2026-03-24T10:49:30.248160Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.

References

Affected packages

Ubuntu:16.04:LTS
virtualbox

Package

Name
virtualbox
Purl
pkg:deb/ubuntu/virtualbox@5.1.38-dfsg-0ubuntu1.16.04.3?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.0.4-dfsg-2
5.0.8-dfsg-1
5.0.10-dfsg-1
5.0.10-dfsg-2
5.0.10-dfsg-3
5.0.10-dfsg-4
5.0.10-dfsg-5
5.0.10-dfsg-6
5.0.10-dfsg-7
5.0.12-dfsg-1
5.0.12-dfsg-2
5.0.14-dfsg-1
5.0.14-dfsg-2
5.0.14-dfsg-2build1
5.0.16-dfsg-2
5.0.16-dfsg-3
5.0.18-dfsg-1
5.0.18-dfsg-1ubuntu1
5.0.18-dfsg-2
5.0.18-dfsg-2build1
5.0.18-dfsg-2ubuntu1
5.0.24-dfsg-0ubuntu1.16.04.1
5.0.32-dfsg-0ubuntu1.16.04.2
5.0.36-dfsg-0ubuntu1.16.04.2
5.0.40-dfsg-0ubuntu1.16.04.1
5.0.40-dfsg-0ubuntu1.16.04.2
5.1.34-dfsg-0ubuntu1.16.04.2
5.1.38-dfsg-0ubuntu1.16.04.1
5.1.38-dfsg-0ubuntu1.16.04.2
5.1.38-dfsg-0ubuntu1.16.04.3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "5.1.38-dfsg-0ubuntu1.16.04.3",
            "binary_name": "virtualbox"
        },
        {
            "binary_version": "5.1.38-dfsg-0ubuntu1.16.04.3",
            "binary_name": "virtualbox-dkms"
        },
        {
            "binary_version": "5.1.38-dfsg-0ubuntu1.16.04.3",
            "binary_name": "virtualbox-guest-dkms"
        },
        {
            "binary_version": "5.1.38-dfsg-0ubuntu1.16.04.3",
            "binary_name": "virtualbox-guest-source"
        },
        {
            "binary_version": "5.1.38-dfsg-0ubuntu1.16.04.3",
            "binary_name": "virtualbox-guest-utils"
        },
        {
            "binary_version": "5.1.38-dfsg-0ubuntu1.16.04.3",
            "binary_name": "virtualbox-guest-x11"
        },
        {
            "binary_version": "5.1.38-dfsg-0ubuntu1.16.04.3",
            "binary_name": "virtualbox-qt"
        },
        {
            "binary_version": "5.1.38-dfsg-0ubuntu1.16.04.3",
            "binary_name": "virtualbox-source"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-25319.json"
Ubuntu:18.04:LTS
virtualbox

Package

Name
virtualbox
Purl
pkg:deb/ubuntu/virtualbox@5.2.42-dfsg-0~ubuntu1.18.04.1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.1.30-dfsg-1
5.2.0-dfsg-1build2
5.2.0-dfsg-2
5.2.0-dfsg-4
5.2.0-dfsg-5
5.2.2-dfsg-2
5.2.2-dfsg-3~build1
5.2.2-dfsg-3
5.2.4-dfsg-1
5.2.4-dfsg-2
5.2.6-dfsg-1
5.2.6-dfsg-2
5.2.6-dfsg-3
5.2.6-dfsg-3build1
5.2.6-dfsg-5
5.2.8-dfsg-2
5.2.8-dfsg-3
5.2.8-dfsg-5
5.2.8-dfsg-6
5.2.8-dfsg-7
5.2.10-dfsg-1
5.2.10-dfsg-2
5.2.10-dfsg-5
5.2.10-dfsg-6
5.2.10-dfsg-6ubuntu18.04.1
5.2.18-dfsg-2~ubuntu18.04.1
5.2.18-dfsg-2~ubuntu18.04.3
5.2.18-dfsg-2~ubuntu18.04.5
5.2.32-dfsg-0~ubuntu18.04.1
5.2.34-dfsg-0~ubuntu18.04.1
5.2.42-dfsg-0~ubuntu1.18.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "5.2.42-dfsg-0~ubuntu1.18.04.1",
            "binary_name": "virtualbox"
        },
        {
            "binary_version": "5.2.42-dfsg-0~ubuntu1.18.04.1",
            "binary_name": "virtualbox-dkms"
        },
        {
            "binary_version": "5.2.42-dfsg-0~ubuntu1.18.04.1",
            "binary_name": "virtualbox-guest-dkms"
        },
        {
            "binary_version": "5.2.42-dfsg-0~ubuntu1.18.04.1",
            "binary_name": "virtualbox-guest-source"
        },
        {
            "binary_version": "5.2.42-dfsg-0~ubuntu1.18.04.1",
            "binary_name": "virtualbox-guest-utils"
        },
        {
            "binary_version": "5.2.42-dfsg-0~ubuntu1.18.04.1",
            "binary_name": "virtualbox-guest-x11"
        },
        {
            "binary_version": "5.2.42-dfsg-0~ubuntu1.18.04.1",
            "binary_name": "virtualbox-qt"
        },
        {
            "binary_version": "5.2.42-dfsg-0~ubuntu1.18.04.1",
            "binary_name": "virtualbox-source"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-25319.json"
Ubuntu:20.04:LTS
virtualbox

Package

Name
virtualbox
Purl
pkg:deb/ubuntu/virtualbox@6.1.50-dfsg-1~ubuntu1.20.04.1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.0.14-dfsg-1
6.0.14-dfsg-2~build1
6.0.14-dfsg-2
6.1.0-dfsg-3build1
6.1.0-dfsg-3build2
6.1.2-dfsg-1
6.1.2-dfsg-1build1
6.1.4-dfsg-1
6.1.4-dfsg-2~build1
6.1.4-dfsg-2
6.1.4-dfsg-4
6.1.6-dfsg-1
6.1.10-dfsg-1~ubuntu1.20.04.1
6.1.16-dfsg-6~ubuntu1.20.04.1
6.1.16-dfsg-6~ubuntu1.20.04.2
6.1.22-dfsg-2~ubuntu1.20.04.1
6.1.26-dfsg-3~ubuntu1.20.04.1
6.1.26-dfsg-3~ubuntu1.20.04.2
6.1.32-dfsg-1~ubuntu1.20.04.1
6.1.34-dfsg-3~ubuntu1.20.04.1
6.1.38-dfsg-3~ubuntu1.20.04.1
6.1.48-dfsg-1~ubuntu1.20.04.1
6.1.50-dfsg-1~ubuntu1.20.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "6.1.50-dfsg-1~ubuntu1.20.04.1",
            "binary_name": "virtualbox"
        },
        {
            "binary_version": "6.1.50-dfsg-1~ubuntu1.20.04.1",
            "binary_name": "virtualbox-dkms"
        },
        {
            "binary_version": "6.1.50-dfsg-1~ubuntu1.20.04.1",
            "binary_name": "virtualbox-guest-dkms"
        },
        {
            "binary_version": "6.1.50-dfsg-1~ubuntu1.20.04.1",
            "binary_name": "virtualbox-guest-source"
        },
        {
            "binary_version": "6.1.50-dfsg-1~ubuntu1.20.04.1",
            "binary_name": "virtualbox-guest-utils"
        },
        {
            "binary_version": "6.1.50-dfsg-1~ubuntu1.20.04.1",
            "binary_name": "virtualbox-guest-x11"
        },
        {
            "binary_version": "6.1.50-dfsg-1~ubuntu1.20.04.1",
            "binary_name": "virtualbox-qt"
        },
        {
            "binary_version": "6.1.50-dfsg-1~ubuntu1.20.04.1",
            "binary_name": "virtualbox-source"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-25319.json"
Ubuntu:22.04:LTS
virtualbox

Package

Name
virtualbox
Purl
pkg:deb/ubuntu/virtualbox@6.1.50-dfsg-1~ubuntu1.22.04.3?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.1.26-dfsg-4
6.1.28-dfsg-1
6.1.30-dfsg-1
6.1.32-dfsg-1
6.1.32-dfsg-1build1
6.1.34-dfsg-3~ubuntu1.22.04.1
6.1.38-dfsg-3~ubuntu1.22.04.1
6.1.48-dfsg-1~ubuntu1.22.04.1
6.1.50-dfsg-1~ubuntu1.22.04.1
6.1.50-dfsg-1~ubuntu1.22.04.3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "6.1.50-dfsg-1~ubuntu1.22.04.3",
            "binary_name": "virtualbox"
        },
        {
            "binary_version": "6.1.50-dfsg-1~ubuntu1.22.04.3",
            "binary_name": "virtualbox-dkms"
        },
        {
            "binary_version": "6.1.50-dfsg-1~ubuntu1.22.04.3",
            "binary_name": "virtualbox-guest-utils"
        },
        {
            "binary_version": "6.1.50-dfsg-1~ubuntu1.22.04.3",
            "binary_name": "virtualbox-guest-x11"
        },
        {
            "binary_version": "6.1.50-dfsg-1~ubuntu1.22.04.3",
            "binary_name": "virtualbox-qt"
        },
        {
            "binary_version": "6.1.50-dfsg-1~ubuntu1.22.04.3",
            "binary_name": "virtualbox-source"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-25319.json"
Ubuntu:24.04:LTS
virtualbox

Package

Name
virtualbox
Purl
pkg:deb/ubuntu/virtualbox@7.0.16-dfsg-2ubuntu1.3?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*
7.0.10-dfsg-3
7.0.12-dfsg-1
7.0.12-dfsg-1build1
7.0.14-dfsg-1
7.0.14-dfsg-2
7.0.14-dfsg-4
7.0.14-dfsg-4build4
7.0.14-dfsg-4build5
7.0.16-dfsg-1
7.0.16-dfsg-2
7.0.16-dfsg-2ubuntu1
7.0.16-dfsg-2ubuntu1.1
7.0.16-dfsg-2ubuntu1.3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "7.0.16-dfsg-2ubuntu1.3",
            "binary_name": "virtualbox"
        },
        {
            "binary_version": "7.0.16-dfsg-2ubuntu1.3",
            "binary_name": "virtualbox-dkms"
        },
        {
            "binary_version": "7.0.16-dfsg-2ubuntu1.3",
            "binary_name": "virtualbox-guest-utils"
        },
        {
            "binary_version": "7.0.16-dfsg-2ubuntu1.3",
            "binary_name": "virtualbox-guest-x11"
        },
        {
            "binary_version": "7.0.16-dfsg-2ubuntu1.3",
            "binary_name": "virtualbox-qt"
        },
        {
            "binary_version": "7.0.16-dfsg-2ubuntu1.3",
            "binary_name": "virtualbox-source"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-25319.json"
Ubuntu:25.10
virtualbox

Package

Name
virtualbox
Purl
pkg:deb/ubuntu/virtualbox@7.2.2-dfsg-2ubuntu0.1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*
7.0.20-dfsg-1.2
7.0.26-dfsg-1
7.1.8-dfsg-2
7.1.8-dfsg-3
7.1.8-dfsg-3build1
7.1.10-dfsg-1
7.1.12-dfsg-1
7.1.12-dfsg-2
7.2.0-dfsg-2
7.2.0-dfsg-3
7.2.2-dfsg-2
7.2.2-dfsg-2ubuntu0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "7.2.2-dfsg-2ubuntu0.1",
            "binary_name": "virtualbox"
        },
        {
            "binary_version": "7.2.2-dfsg-2ubuntu0.1",
            "binary_name": "virtualbox-dkms"
        },
        {
            "binary_version": "7.2.2-dfsg-2ubuntu0.1",
            "binary_name": "virtualbox-guest-utils"
        },
        {
            "binary_version": "7.2.2-dfsg-2ubuntu0.1",
            "binary_name": "virtualbox-guest-utils-hwe"
        },
        {
            "binary_version": "7.2.2-dfsg-2ubuntu0.1",
            "binary_name": "virtualbox-guest-x11"
        },
        {
            "binary_version": "7.2.2-dfsg-2ubuntu0.1",
            "binary_name": "virtualbox-guest-x11-hwe"
        },
        {
            "binary_version": "7.2.2-dfsg-2ubuntu0.1",
            "binary_name": "virtualbox-qt"
        },
        {
            "binary_version": "7.2.2-dfsg-2ubuntu0.1",
            "binary_name": "virtualbox-source"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-25319.json"