*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Seth Arnold (seth-arnold):

Looks like VirtualBox <=5.2.20 is vulnerable:

https://github.com/MorteNoir1/virtualbox_e1000_0day

I'm not a security expert but this looks serious to me. cosmic is still
shipping 5.2.18. Are there any plans to upgrade to 5.2.22 or patch this?

According to my understanding the following patch fixes the issue:

https://www.virtualbox.org/changeset/75330/vbox

Have you considered adding this to the patch queue? Let me know if you
want me to prepare a MR.

P.S.: Although this is all over the Internet it seems like Oracle is
keeping this quiet [1]. No hint that this commit fixes a security issue,
no mention in the change log [2]. As far as I can tell not even a CVE
number has been assigned.

[1] 
https://forums.virtualbox.org/viewtopic.php?f=1&t=90235&p=433202&hilit=mortenoir1#p433237
[2] https://www.virtualbox.org/wiki/Changelog-5.2#v22

** Affects: virtualbox (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: community-security
-- 
E1000 guest to host escape
https://bugs.launchpad.net/bugs/1809156
You received this bug notification because you are a member of Ubuntu Bugs, 
which is subscribed to the bug report.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to