Oracle has released a patch for the virtualization system VirtualBox 7.1.12, which includes 11 changes and addresses 7 vulnerabilities. The three most serious issues have been assigned a severity level of 8.2 out of 10:
- CVE-2025-53024 — integer overflow in the implementation of the VMSVGA virtual device, leading to writing data beyond the allocated buffer when processing user-provided data. This vulnerability allows a privileged user of the guest system to execute code at the hypervisor level and gain access to the host environment.
- CVE-2025-53027 — improper use of locks in the implementation of the OHCI USB virtual controller, allowing code execution at the hypervisor level through manipulation of the guest system.
- CVE-2025-53028 — buffer overflow in the implementation of the VMSVGA virtual device, allowing code execution at the hypervisor level through manipulation of the guest system.
Vulnerabilities CVE-2025-53025 and CVE-2025-53026, which have been assigned a severity level of 6 out of 10, lead to information leakage of residual memory content from the host environment components due to inadequate memory initialization in the LSILogic and BusLogic modules.
Non-security related changes:
- The additions for hosts and guest systems with Linux include fixes for support of the developing Linux kernel 6.16.
- In the additions for guest systems with Linux, issues encountered while using Linux kernels prior to version 3.10, as well as 2.6.x series kernels, have been resolved.
- In the additions for Linux-based host systems, an issue causing the kernel to enter a panic state when using network bridges with interfaces based on the ixgbe driver has been resolved.
- In the manager of virtual machines Issues with nested virtual machine launches have been resolved.
- A bug in NAT that caused failures when starting virtual machines with long names has been fixed.
- In the additions for Windows-based host systems, driver installation has been improved, and guest systems are now informed about the support for AVX/AVX2 extensions when using the Hyper-V hypervisor. An issue leading to a 'blue screen of death' when closing the VirtualBox GUI after removing the package with VirtualBox components for host environments has been resolved.
- The issue preventing the launch of Windows guest systems when output recording was enabled in display settings has been resolved.
Source: opennet.ru
