Unrated severityNVD Advisory· Published May 5, 2021· Updated Sep 16, 2024
virtualbox: missing sticky bit for /etc/vbox allows local root exploit for members of vboxusers group
CVE-2021-25319
Description
A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.
Affected products
5- osv-coords4 versionspkg:rpm/opensuse/virtualbox&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/virtualbox&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/virtualbox-kmp&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/virtualbox-kmp&distro=openSUSE%20Leap%2015.3
< 6.1.22-lp152.2.24.2+ 3 more
- (no CPE)range: < 6.1.22-lp152.2.24.2
- (no CPE)range: < 6.1.22-lp153.2.3.2
- (no CPE)range: < 6.1.22-lp152.2.24.2
- (no CPE)range: < 6.1.22-lp153.2.3.2
- openSUSE/Factoryv5Range: virtualbox
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- bugzilla.suse.com/show_bug.cgimitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.