openSUSE-SU-2021:0630-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:0630-1
openSUSE-SU-2021:0630-1
Summary: Security update for virtualbox
Details: This update for virtualbox fixes the following issues: - Version bump to 6.1.20 (released April 20 2021 by Oracle) Fixes boo#1183329 'virtualbox 6.1.18 crashes when it runs nested VM' Fixes boo#1183125 'Leap 15.3 installation in Virtualbox without VBox integration' Fixes CVE-2021-2264 and boo#1184542. The directory for the <user>.start files for autostarting VMs is moved from /etc/vbox to /etc/vbox/autostart.d. In addition, the autostart service is hardened (by Oracle). - change the modalias for guest-tools and guest-x11 to get them to autoinstall. - Own %{_sysconfdir}/X11/xinit/xinitrc.d as default packages (eg systemd) no longer do so, breaking package build. - Update fixes_for_leap15.3 for kernel API changes between 5.3.18-45 and 5.3.18-47. - update-extpack.sh: explicitly use https:// protocol for authenticity. The http:// URL is currently redirected to https:// but don't rely on this. - Add code to generate guest modules for Leap 15.2 and Leap 15.3. The kernel versions do not allow window resizing. Files 'virtualbox-kmp-files-leap' and 'vboxguestconfig.sh' are added - Fixes CVE-2021-2074, boo#1181197 and CVE-2021-2129, boo#1181198. - Under some circumstances, shared folders are mounted as root.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/2RTNW7ZRCP2VD6YMPAHFC7MY4YIB5GTL/, https://bugzilla.suse.com/1181197, https://bugzilla.suse.com/1181198, https://bugzilla.suse.com/1183125, https://bugzilla.suse.com/1183329, https://bugzilla.suse.com/1184542, https://www.suse.com/security/cve/CVE-2021-2074, https://www.suse.com/security/cve/CVE-2021-2129, https://www.suse.com/security/cve/CVE-2021-2264
Affected packages
Package
Name: virtualbox
Purl: pkg:rpm/opensuse/virtualbox&distro=openSUSE%20Leap%2015.2
Affected ranges
Type: ECOSYSTEM
Events:
