#1142643 virtualbox: CVE-2026-47041 CVE-2026-47043 CVE-2026-47044 CVE-2026-47047 CVE-2026-47050 CVE-2026-47053 CVE-2026-47054 CVE-2026-47055 CVE-2026-47062 CVE-2026-60150 CVE-2026-60155 CVE-2026-60158 CVE-2026-60159 CVE-2026-60160 CVE-2026-60161 CVE-2026-60162

Package:
src:virtualbox
Source:
src:virtualbox
Submitter:
Salvatore Bonaccorso
Date:
2026-07-29 16:12:19 UTC
Severity:
normal
Tags:
#1142643#5
Date:
2026-07-23 12:20:23 UTC
From:
To:
Hi,

The following vulnerabilities were published for virtualbox.

CVE-2026-47041[0]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in unauthorized ability to cause a
| hang or frequently repeatable crash (complete DOS) of Oracle VM
| VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts).  CVSS
| Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).


CVE-2026-47043[1]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in  unauthorized read access to a
| subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score
| 3.2 (Confidentiality impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).


CVE-2026-47044[2]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows low
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  Successful
| attacks of this vulnerability can result in unauthorized ability to
| cause a hang or frequently repeatable crash (complete DOS) of Oracle
| VM VirtualBox. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS
| Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-47047[3]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows low
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  Successful
| attacks of this vulnerability can result in takeover of Oracle VM
| VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and
| Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).


CVE-2026-47050[4]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.8. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  Successful
| attacks require human interaction from a person other than the
| attacker and while the vulnerability is in Oracle VM VirtualBox,
| attacks may significantly impact additional products (scope change).
| Successful attacks of this vulnerability can result in  unauthorized
| creation, deletion or modification access to critical data or all
| Oracle VM VirtualBox accessible data and unauthorized ability to
| cause a hang or frequently repeatable crash (complete DOS) of Oracle
| VM VirtualBox. CVSS 3.1 Base Score 7.4 (Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H).


CVE-2026-47053[5]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows low
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  Successful
| attacks require human interaction from a person other than the
| attacker. Successful attacks of this vulnerability can result in
| unauthorized creation, deletion or modification access to critical
| data or all Oracle VM VirtualBox accessible data and unauthorized
| ability to cause a partial denial of service (partial DOS) of Oracle
| VM VirtualBox. CVSS 3.1 Base Score 5.6 (Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L).


CVE-2026-47054[6]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows low
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  Successful
| attacks of this vulnerability can result in takeover of Oracle VM
| VirtualBox. Note: This vulnerability applies to Windows host only.
| CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).


CVE-2026-47055[7]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in  unauthorized update, insert or
| delete access to some of Oracle VM VirtualBox accessible data. CVSS
| 3.1 Base Score 3.2 (Integrity impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N).


CVE-2026-47062[8]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows low
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  Successful
| attacks of this vulnerability can result in unauthorized ability to
| cause a hang or frequently repeatable crash (complete DOS) of Oracle
| VM VirtualBox. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS
| Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).


CVE-2026-60150[9]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows low
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  Successful
| attacks of this vulnerability can result in takeover of Oracle VM
| VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and
| Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).


CVE-2026-60155[10]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Difficult to exploit vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in takeover of Oracle VM VirtualBox.
| CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).


CVE-2026-60158[11]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Difficult to exploit vulnerability allows low
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in  unauthorized creation, deletion or
| modification access to critical data or all Oracle VM VirtualBox
| accessible data and unauthorized ability to cause a partial denial
| of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base
| Score 6.4 (Integrity and Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L).


CVE-2026-60159[12]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Difficult to exploit vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in takeover of Oracle VM VirtualBox.
| CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability
| impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).


CVE-2026-60160[13]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in  unauthorized read access to a
| subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score
| 3.2 (Confidentiality impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).


CVE-2026-60161[14]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Easily exploitable vulnerability allows
| unauthenticated attacker with logon to the infrastructure where
| Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.
| Successful attacks require human interaction from a person other
| than the attacker. Successful attacks of this vulnerability can
| result in unauthorized ability to cause a hang or frequently
| repeatable crash (complete DOS) of Oracle VM VirtualBox as well as
| unauthorized update, insert or delete access to some of Oracle VM
| VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and
| Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H).


CVE-2026-60162[15]:
| Vulnerability in the Oracle VM VirtualBox product of Oracle
| Virtualization (component: Core).   The supported version that is
| affected is 7.2.12. Difficult to exploit vulnerability allows high
| privileged attacker with logon to the infrastructure where Oracle VM
| VirtualBox executes to compromise Oracle VM VirtualBox.  While the
| vulnerability is in Oracle VM VirtualBox, attacks may significantly
| impact additional products (scope change).  Successful attacks of
| this vulnerability can result in  unauthorized access to critical
| data or complete access to all Oracle VM VirtualBox accessible data
| and unauthorized ability to cause a partial denial of service
| (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.1
| (Confidentiality and Availability impacts).  CVSS Vector:
| (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L).


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-47041
https://www.cve.org/CVERecord?id=CVE-2026-47041
[1] https://security-tracker.debian.org/tracker/CVE-2026-47043
https://www.cve.org/CVERecord?id=CVE-2026-47043
[2] https://security-tracker.debian.org/tracker/CVE-2026-47044
https://www.cve.org/CVERecord?id=CVE-2026-47044
[3] https://security-tracker.debian.org/tracker/CVE-2026-47047
https://www.cve.org/CVERecord?id=CVE-2026-47047
[4] https://security-tracker.debian.org/tracker/CVE-2026-47050
https://www.cve.org/CVERecord?id=CVE-2026-47050
[5] https://security-tracker.debian.org/tracker/CVE-2026-47053
https://www.cve.org/CVERecord?id=CVE-2026-47053
[6] https://security-tracker.debian.org/tracker/CVE-2026-47054
https://www.cve.org/CVERecord?id=CVE-2026-47054
[7] https://security-tracker.debian.org/tracker/CVE-2026-47055
https://www.cve.org/CVERecord?id=CVE-2026-47055
[8] https://security-tracker.debian.org/tracker/CVE-2026-47062
https://www.cve.org/CVERecord?id=CVE-2026-47062
[9] https://security-tracker.debian.org/tracker/CVE-2026-60150
https://www.cve.org/CVERecord?id=CVE-2026-60150
[10] https://security-tracker.debian.org/tracker/CVE-2026-60155
https://www.cve.org/CVERecord?id=CVE-2026-60155
[11] https://security-tracker.debian.org/tracker/CVE-2026-60158
https://www.cve.org/CVERecord?id=CVE-2026-60158
[12] https://security-tracker.debian.org/tracker/CVE-2026-60159
https://www.cve.org/CVERecord?id=CVE-2026-60159
[13] https://security-tracker.debian.org/tracker/CVE-2026-60160
https://www.cve.org/CVERecord?id=CVE-2026-60160
[14] https://security-tracker.debian.org/tracker/CVE-2026-60161
https://www.cve.org/CVERecord?id=CVE-2026-60161
[15] https://security-tracker.debian.org/tracker/CVE-2026-60162
https://www.cve.org/CVERecord?id=CVE-2026-60162

Regards,
Salvatore

#1142643#10
Date:
2026-07-29 16:05:46 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
virtualbox, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142643@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Gianfranco Costamagna <locutusofborg@debian.org> (supplier of updated virtualbox package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 29 Jul 2026 15:29:13 +0200
Source: virtualbox
Built-For-Profiles: noudeb
Architecture: source
Version: 7.2.14-dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Virtualbox Team <team+debian-virtualbox@tracker.debian.org>
Changed-By: Gianfranco Costamagna <locutusofborg@debian.org>
Closes: 1014394 1023603 1045194 1050406 1064225 1104227 1138419 1140286 1140302 1140838 1141114 1142527 1142643
Changes:
 virtualbox (7.2.14-dfsg-1) unstable; urgency=medium
 .
   * New upstream version 7.2.14-dfsg
     (Closes: #1142527, #1014394, #1023603, #1045194, #1050406, #1064225)
     (Closes: #1140302, #1142643, #1140286, #1140838, #1141114)
   * Strip also libssl/openssl from upstream tarball
   * Switch from yasm/nasm to only nasm
     (Closes: #1104227)
   * Fix build with Openssl 4.0 (Closes: #1138419)
Checksums-Sha1:
 675edaefa55d5ebb4fa340edff6b020cbf0c961a 3893 virtualbox_7.2.14-dfsg-1.dsc
 989878e25796ab30c11b1fccb0f9b2e98276648b 106712004 virtualbox_7.2.14-dfsg.orig.tar.xz
 7d2d28b681f54f013b8ae9a841b6f9ceb1a32a15 84276 virtualbox_7.2.14-dfsg-1.debian.tar.xz
 ebb3833f9c9415818aaabf34462981c1f7389178 29262 virtualbox_7.2.14-dfsg-1_source.buildinfo
Checksums-Sha256:
 b8b30cf076c1db83e0688833509371fb9efd75a3210401b27ff4e9b07bd4f378 3893 virtualbox_7.2.14-dfsg-1.dsc
 7756f1939fadccaf783b5dc268abaf2e55fc05f12af90944cba3d473595d4907 106712004 virtualbox_7.2.14-dfsg.orig.tar.xz
 2add8b8e74c6f7d917f4b2f809b5c1b7a9ad7caff37504e00638c3324aab59ca 84276 virtualbox_7.2.14-dfsg-1.debian.tar.xz
 3ec433c8d8cae658fbd255911069f5fa4b384a65f26ce38c5912ac195ec7fbfe 29262 virtualbox_7.2.14-dfsg-1_source.buildinfo
Files:
 801202f9fb86ad2018426b020175c9ee 3893 contrib/misc - virtualbox_7.2.14-dfsg-1.dsc
 c151d7824a0bd1e10b1296338233305e 106712004 contrib/misc - virtualbox_7.2.14-dfsg.orig.tar.xz
 49e08517e1135569588b40f9578cf1c6 84276 contrib/misc - virtualbox_7.2.14-dfsg-1.debian.tar.xz
 913aa095a6f0b451fc06cb0ea903dec2 29262 contrib/misc - virtualbox_7.2.14-dfsg-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJNBAEBCgA3FiEEkpeKbhleSSGCX3/w808JdE6fXdkFAmpqIJQZHGxvY3V0dXNv
ZmJvcmdAZGViaWFuLm9yZwAKCRDzTwl0Tp9d2eLfD/4qsoanID9jjQJDS8HOHlS7
jqMvm+ADyrlNkgsgI9XD+LNjFwVAWDF9GPYAFm8NOnm/ssP6qQGUH5qI5h8xIUZg
XRl4UcNpyBGhY6W1P9Jc3z4l4ve6jjMC5z7Rv/sL5xFsasyFLuqsx6ZVkmqUA9n7
0Dz5kc9PdFtvpejfQxpLBFPjoCuow9eRdPplhqDYmF6xbAoSTj6j+3q04KvmOAdC
nEWCvuUapwTa26/jM8sm8iSgYiqpK1CydjQQzj76v2NETwrg5f0EO9TAn7eADbit
XQ83c7xtotYRDZ6AsSkGSLfh6/StBKqZUCJkVz/xhglbmS/7hKUtpsQoV+anHrDz
c1yyU8VDQEXENdkERftgwWTO7sLMELnIUwDWj3Ijepr+iu0/WlzeGKZkSpwWB1q3
GZWoHUD4TIv+4wD8SN/f0PIpeMiijeBVJUUHqNMCH8M7Yl3iQp5Zs16x1Xdn6/Ze
JqKWM+xPVO+bV1qcIX+mQ6rNgSjf0WgSMo8WcXqi3neCArs7PMUCnZzpi45Xh+0i
njEo/MU/OwPB5wPh0iTZEa6YXTCugdDAlBipAgZQA2A3sFtMVNyEf935hg8P2z3R
yED7JJRRbBpG3AXKTgBCKU6XA6h9eFCV/7dqDzaJzwHOJ9AHYVnN6V5Eq/33qQ+p
KW4o0Zg9L+tG21jR9QcmzQ==
=UK43
-----END PGP SIGNATURE-----