Oracle has released a corrective update for the virtualization system VirtualBox 7.2.8, addressing 9 vulnerabilities, details of which have not yet been disclosed. It is noted that 5 of the most serious issues have a severity level of 7.5 out of 10. One of the vulnerabilities can be exploited remotely over the network. In addition to the vulnerabilities, the new version includes 17 changes:
- In the add-ons for host environments with Linux, initial support for Linux kernels 6.19 and 7.0 has been added, as well as accounting for CPU time spent on guest systems (when monitoring system load, guest systems are now tracked separately rather than as time spent running the Linux kernel).
- In the add-ons for guest systems with Linux, the vboxvideo kernel module included in the distribution is deprecated for use with kernels 7.0 and newer (it remains supported for older kernels). Instead of this module, on systems with kernel 7.0, the virtual graphics adapter VMSVGA or the vboxvideo module from the main Linux kernel should be used.
- In the add-ons for guest systems, issues with accessing the clipboard and pasting from the clipboard when launching the guest system with a graphical environment based on Wayland on host systems with Windows have been resolved. The problem with the last character missing from the text when copied in Windows via the clipboard from Linux with Wayland has also been fixed.
- In the add-ons for host environments and guest systems with Linux, support for UEK9 kernel packages from Oracle Linux 9 has been added, and issues with kernels from RHEL 10.1 and 10.2 have been resolved. The operation of the commands 'rcvboxdrv setup' and 'rcvboxadd setup' has been improved, and the installation process has been accelerated.
- A crash occurring when using multiple devices connected to the LSI Logic SAS controller in FreeBSD 16 has been resolved.
- In the address translator, a problem that prevented access to the internal DNS server has been fixed.
- In the graphical subsystem, an issue with the cursor shape freezing, which stopped changing based on the context in guest systems with Ubuntu 25.10 and Wayland, has been resolved.
- In the add-ons for guest systems with Windows, an issue leading to a crash (BSOD), resulting in the error DRIVER_OVERRAN_STACK_BUFFER, has been addressed.
- The UEFI components have fixed issues related to updating the certificate for UEFI Secure Boot and booting guest systems with Windows 11.
Source: opennet.ru
