Oracle has released a patch for the virtualization system , which notes . Concurrently released are corrective updates for VirtualBox 6.0.20 and 5.2.40. The updates address , of which 7 issues have a critical severity level (CVSS greater than 8). This includes vulnerabilities exploited in attacks demonstrated at conferences and allowing manipulation on the guest system side to gain access to the host system and execute code with hypervisor privileges.
Changes unrelated to security in release 6.1.6:
- Support for Linux kernel 5.6 has been added to the host environment components and guest system extensions;
- Improved support for 2D and 3D acceleration, as well as rendering;
- User interface enhancements and updated visual elements have been made;
- Issues with screen resizing and handling multi-monitor configurations that appear in guest systems with X11
and the virtual graphics adapter VMSVGA have been resolved; - The stability and performance of the USB subsystem have been improved;
- Error handling in the serial port driver has been enhanced, resolving hangs that occur when the host system's port disappears;
- Corrections related to guestcontrol operations have been made in VBoxManage;
- An issue with exception handling in Python bindings has been fixed in the API;
- Errors in the clipboard sharing subsystem have been resolved, and support for HTML data has been added.
Source: opennet.ru
