PT-2024-5869 · Oracle+2 · Virtualbox+2

Derek Schrock

+1

·

Published

2024-07-16

·

Updated

2025-10-10

·

CVE-2024-21161

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Oracle VM VirtualBox versions prior to 7.0.20
Description The issue is related to errors in resource release in the Core component of Oracle VM VirtualBox, allowing a low-privileged attacker with logon to the infrastructure to compromise Oracle VM VirtualBox. Successful attacks can result in unauthorized ability to cause a hang or frequently repeatable crash of Oracle VM VirtualBox. This issue applies to Linux hosts only.
Recommendations For versions prior to 7.0.20, update to version 7.0.20 or later to resolve the issue. As a temporary workaround, consider restricting access to the Core component of Oracle VM VirtualBox to minimize the risk of exploitation. Additionally, ensure that Oracle VM VirtualBox is running with the least privileges necessary to reduce the impact of a potential attack.

Fix

DoS

Resource Exhaustion

Improper Resource Release

Weakness Enumeration

Related Identifiers

ALT-PU-2024-14700
ALT-PU-2024-14702
ALT-PU-2024-14703
ALT-PU-2024-15438
ALT-PU-2024-15440
ALT-PU-2024-15441
ALT-PU-2024-15442
ALT-PU-2024-15443
ALT-PU-2024-15782
ALT-PU-2024-15784
ALT-PU-2025-12585
ALT-PU-2025-12587
ALT-PU-2025-12588
ALT-PU-2025-12589
ALT-PU-2025-12590
BDU:2024-06651
CVE-2024-21161
MGASA-2024-0275

Affected Products

Alt Linux
Virtualbox
Red Os