High severity7.8NVD Advisory· Published May 5, 2021· Updated Jun 17, 2026
CVE-2021-25319
CVE-2021-25319
Description
A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- Range: <=6.1.20-1.1
- osv-coords4 versionspkg:rpm/opensuse/virtualbox&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/virtualbox&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/virtualbox-kmp&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/virtualbox-kmp&distro=openSUSE%20Leap%2015.3
< 6.1.22-lp152.2.24.2+ 3 more
- (no CPE)range: < 6.1.22-lp152.2.24.2
- (no CPE)range: < 6.1.22-lp153.2.3.2
- (no CPE)range: < 6.1.22-lp152.2.24.2
- (no CPE)range: < 6.1.22-lp153.2.3.2
Patches
Vulnerability mechanics
References
1- bugzilla.suse.com/show_bug.cginvdIssue TrackingPatchVendor Advisory
News mentions
0No linked articles in our index yet.