openSUSE-SU-2021:1393-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:1393-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2021:1393-1
Upstream
CVE (5)
  • CVE-2021-2475
  • CVE-2021-35538
  • CVE-2021-35540
  • CVE-2021-35542
  • CVE-2021-35545
Related
Published
2021-10-26T10:00:51Z
Modified
2026-02-04T04:24:51Z
Summary
Security update for virtualbox
Details

This update for virtualbox fixes the following issues:

Version bump to 6.1.28 (released October 19 2021 by Oracle)

This is a maintenance release. The following items were fixed and/or added:

  • VMM: Fixed guru meditation while booting nested-guests accessing debug registers under certain conditions

  • UI: Bug fixes for touchpad-based scrolling

  • VMSVGA: Fixed VM black screen issue on first resize after restoring from saved state (bug #20067)

  • VMSVGA: Fixed display corruption on Linux Mint (bug #20513)

  • Storage: Fixed a possible write error under certain circumstances when using VHD images (bug #20512)

  • Network: Multiple updates in virtio-net device support

  • Network: Disconnecting cable in saved VM state now is handled properly by virtio-net

  • Network: More administrative control over network ranges, see user manual

  • NAT: Fixed not rejecting TFTP requests with absolute pathnames (bug #20589)

  • Audio: Fixed VM session aborting after PC hibernation (bug #20516)

  • Audio: Fixed setting the line-in volume of the HDA emulation on modern Linux guests

  • Audio: Fixed resuming playback of the AC'97 emulation while a snapshot has been taken

  • API: Added bindings support for Python 3.9 (bug #20252)

  • API: Fixed rare hang of VM when changing settings at runtime

  • Linux host: Improved kernel modules installation detection which prevents unnecessary modules rebuild

  • Host Services: Shared Clipboard: Prevent guest clipboard reset when clipboard sharing is disabled (bug #20487)

  • Host Services: Shared Clipboard over VRDP: Fixed to continue working when guest service reconnects to host (bug #20366)

  • Host Services: Shared Clipboard over VRDP: Fixed preventing remote RDP client to hang when guest has no clipboard data to report

  • Linux Host and Guest: Introduced initial support for kernels 5.14 and 5.15

  • Linux Host and Guest: Introduced initial support for RHEL 8.5 kernel

  • Windows Guest: Introduced Windows 11 guest support, including unattended installation

  • Fixes CVE-2021-35538, CVE-2021-35545, CVE-2021-35540, CVE-2021-35542, and CVE-2021-2475 (boo#1191869)

  • Use kernel_module_directory macro for kernel modules (boo#1191526)

  • Finish UsrMerge for VirtualBox components (boo#1191104).

References

Affected packages

openSUSE:Leap 15.3 / virtualbox

Package

Name
virtualbox
Purl
pkg:rpm/opensuse/virtualbox&distro=openSUSE%20Leap%2015.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.1.28-lp153.2.12.1

Ecosystem specific

{
    "binaries":  [
        {
            "python3-virtualbox":  "6.1.28-lp153.2.12.1",
            "virtualbox":  "6.1.28-lp153.2.12.1",
            "virtualbox-devel":  "6.1.28-lp153.2.12.1",
            "virtualbox-guest-desktop-icons":  "6.1.28-lp153.2.12.1",
            "virtualbox-guest-source":  "6.1.28-lp153.2.12.1",
            "virtualbox-guest-tools":  "6.1.28-lp153.2.12.1",
            "virtualbox-guest-x11":  "6.1.28-lp153.2.12.1",
            "virtualbox-host-source":  "6.1.28-lp153.2.12.1",
            "virtualbox-kmp-default":  "6.1.28_k5.3.18_59.27-lp153.2.12.1",
            "virtualbox-kmp-preempt":  "6.1.28_k5.3.18_59.27-lp153.2.12.1",
            "virtualbox-qt":  "6.1.28-lp153.2.12.1",
            "virtualbox-vnc":  "6.1.28-lp153.2.12.1",
            "virtualbox-websrv":  "6.1.28-lp153.2.12.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:1393-1.json"

openSUSE:Leap 15.3 / virtualbox-kmp

Package

Name
virtualbox-kmp
Purl
pkg:rpm/opensuse/virtualbox-kmp&distro=openSUSE%20Leap%2015.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.1.28-lp153.2.12.1

Ecosystem specific

{
    "binaries":  [
        {
            "python3-virtualbox":  "6.1.28-lp153.2.12.1",
            "virtualbox":  "6.1.28-lp153.2.12.1",
            "virtualbox-devel":  "6.1.28-lp153.2.12.1",
            "virtualbox-guest-desktop-icons":  "6.1.28-lp153.2.12.1",
            "virtualbox-guest-source":  "6.1.28-lp153.2.12.1",
            "virtualbox-guest-tools":  "6.1.28-lp153.2.12.1",
            "virtualbox-guest-x11":  "6.1.28-lp153.2.12.1",
            "virtualbox-host-source":  "6.1.28-lp153.2.12.1",
            "virtualbox-kmp-default":  "6.1.28_k5.3.18_59.27-lp153.2.12.1",
            "virtualbox-kmp-preempt":  "6.1.28_k5.3.18_59.27-lp153.2.12.1",
            "virtualbox-qt":  "6.1.28-lp153.2.12.1",
            "virtualbox-vnc":  "6.1.28-lp153.2.12.1",
            "virtualbox-websrv":  "6.1.28-lp153.2.12.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:1393-1.json"