PT-2025-4255 · Oracle+2 · Virtualbox+2

·

CVE-2025-21533

·

Published

2025-01-21

·

Updated

2026-06-18

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle VM VirtualBox versions prior to 7.0.24 Oracle VM VirtualBox versions prior to 7.1.6
Description A flaw in the Core component of Oracle VM VirtualBox involves authorization mechanism deficiencies and a speculative store bypass. This allows a low-privileged local attacker with access to the infrastructure where the software executes to compromise the system. Exploitation can be achieved via cache-based side-channel attacks, potentially resulting in unauthorized access to critical data or complete access to all data accessible by Oracle VM VirtualBox.
Recommendations Update to version 7.0.24 or later. Update to version 7.1.6 or later.

Fix

DoS

LPE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12585
ALT-PU-2025-12587
ALT-PU-2025-12588
ALT-PU-2025-12589
ALT-PU-2025-12590
BDU:2025-01284
CVE-2025-21533
MGASA-2025-0027

Affected Products

Alt Linux
Virtualbox
Red Os