*** This bug is a security vulnerability *** You have been subscribed to a public security bug by Seth Arnold (seth-arnold):
Looks like VirtualBox <=5.2.20 is vulnerable: https://github.com/MorteNoir1/virtualbox_e1000_0day I'm not a security expert but this looks serious to me. cosmic is still shipping 5.2.18. Are there any plans to upgrade to 5.2.22 or patch this? According to my understanding the following patch fixes the issue: https://www.virtualbox.org/changeset/75330/vbox Have you considered adding this to the patch queue? Let me know if you want me to prepare a MR. P.S.: Although this is all over the Internet it seems like Oracle is keeping this quiet [1]. No hint that this commit fixes a security issue, no mention in the change log [2]. As far as I can tell not even a CVE number has been assigned. [1] https://forums.virtualbox.org/viewtopic.php?f=1&t=90235&p=433202&hilit=mortenoir1#p433237 [2] https://www.virtualbox.org/wiki/Changelog-5.2#v22 ** Affects: virtualbox (Ubuntu) Importance: Undecided Status: New ** Tags: community-security -- E1000 guest to host escape https://bugs.launchpad.net/bugs/1809156 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
