Database/Kernel, userspace & hypervisor
Oracle VirtualBox: Core component flaw allowing a low-privileged guest user to take over the host VirtualBox
CVSS 7.8CVE-2023-21987Kernel, userspace & hypervisorcurated
Impact
Core component flaw allowing a low-privileged guest user to take over the host VirtualBox installation
Who can reach it
Tenant VM guest
What to do
VirtualBox update + VM restart. VirtualBox is not a production hypervisor - its presence on a neocloud node is itself the finding
References
Related entries
- Oracle VirtualBox: Easily exploitable Core flaw allowing unauthorised access to VirtualBox-accessible dataCVE-2024-21121 · Oracle VirtualBoxMedium
- Linux kernel (io_uring): io_uring fixed-buffer registration gives out-of-bounds access to physical memoryCVE-2023-2598 · Linux kernel (io_uring)High
- Linux kernel (nf_tables): Use-after-free in nft_chain_lookup_byid() - local root (Pwn2Own Vancouver chain)CVE-2023-31248 · Linux kernel (nf_tables)High
- Linux kernel (nf_tables): Use-after-free in nf_tables anonymous-set batch processingCVE-2023-32233 · Linux kernel (nf_tables)High
- Linux kernel (mm VMA): StackRot: privilege escalation via non-RCU-protected VMA traversalCVE-2023-3269 · Linux kernel (mm VMA)High
- Linux kernel (nf_tables): UAF in nft_set_lookup_global after mixed named/anonymous set batches - local rootCVE-2023-3390 · Linux kernel (nf_tables)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.