Release of VirtualBox 6.0.6

Oracle Corporation has created corrective releases of the virtualization system VirtualBox 6.0.6 and 5.2.28, which noted 39 fixes. The new releases also addressed 12 vulnerabilities, of which 7 are critically dangerous (CVSS Score 8.8). Details are not disclosed, but judging by the CVSS level, the issues are demonstrated at the Pwn2Own 2019 competition and allow code execution on the host system from the guest system environment.

Key changes in release 6.0.6:

  • Support for Linux kernels 4.4.169, 5.0, and 5.1 has been added for guest systems and hosts running Linux. A log of the module build results for the Linux kernel has been introduced. Driver compilation for loading in Secure Boot mode has been implemented. The performance and reliability of shared folders have been improved;
  • Minor changes have been made to the user interface. The progress display for snapshot deletion has been set up. Issues with file copying and the display of copy operation progress in the built-in file manager have been fixed. Bugs occurring during automated installation of Ubuntu in guest systems have been addressed;
  • Initial support for the QCOW3 format in read-only mode has been added. Bugs related to reading some QCOW2 images have been fixed;
  • Numerous fixes related to the emulated VMSVGA graphics device have been made. Compatibility of VMSVGA with older X servers has been improved. VMSVGA can now be used when working with EFI firmware interfaces. Issues with the cursor disappearing when integration mouse support is not installed have been resolved.
    Problems with remembering the guest system screen size and using RDP have been addressed;
  • Issues with loading saved states for LsiLogic devices have been resolved;
  • Problems with nested virtualization on systems with AMD processors have been fixed;
  • IDE PCI emulation has been improved, allowing IDE drivers for NetWare to operate using bus-mastering mode;
  • For the DirectSound backend, the capability to enumerate existing sound devices has been added;
  • In the network subsystem, issues with packet padding when using Windows on the host side have been resolved;
  • Problems with serial port emulation have been fixed.
  • Fixed an issue that led to the duplication of shared folders after restoring a virtual machine from a saved state;
  • Resolved problems with file copying between the host and guest system in Drag and drop mode;
  • Eliminated a crash when using VBoxManage;
  • Fixed an issue that caused freezes when attempting to start a virtual machine after a failure;
  • In Windows guest systems, issues with using complex screen configurations with the WDDM driver have been resolved (fixed freezes in Skype for Business and crashes of guest systems with WDDM);
  • Improved support for shared folders in guest systems running OS/2;
  • Java 11 support has been added to web services;
  • Compilation with LibreSSL has been established;
  • Resolved build issues for FreeBSD.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster