Does this vulnerability affect VirtualBox?

This is for discussing general topics about how to use VirtualBox.
Post Reply
DNS
Posts: 107
Joined: 2. May 2011, 00:16
Primary OS: MS Windows 7
VBox Version: VirtualBox+Oracle ExtPack
Guest OSses: xp win7

Does this vulnerability affect VirtualBox?

Post by DNS »

Hi, I came across an advisory for a priviledge escalation vuln that is realated to how 64bit Intel chips handle stack frames. Can a dev please comment on whether this affects virtualBox or not?

Please check out the details here:
http://www.kb.cert.org/vuls/id/649219

According to the prodcut listing Xen is affected - but its a paravirtualizer so things may be very well different for full virualizers. Also Oracle corp. is listed as one of the informed parties but it doesn't exactly state which products are affected; maybe just the Xen based Oracle VM?
Perryg
Site Moderator
Posts: 34369
Joined: 6. Sep 2008, 22:55
Primary OS: Linux other
VBox Version: OSE self-compiled
Guest OSses: *NIX

Re: Does this vulnerability affect VirtualBox?

Post by Perryg »

As you said VirtualBox is not Xen, but regardless you probably will not hear about it here. Security issues are treated in secret and Oracle prevents anyone from talking about them in public. I am certain that the DEVs are fully aware of the notice.
DNS
Posts: 107
Joined: 2. May 2011, 00:16
Primary OS: MS Windows 7
VBox Version: VirtualBox+Oracle ExtPack
Guest OSses: xp win7

Re: Does this vulnerability affect VirtualBox?

Post by DNS »

Does that mean they will never list it as fixed even after a patch is issued?
Perryg
Site Moderator
Posts: 34369
Joined: 6. Sep 2008, 22:55
Primary OS: Linux other
VBox Version: OSE self-compiled
Guest OSses: *NIX

Re: Does this vulnerability affect VirtualBox?

Post by Perryg »

If it is deemed to be an issue and you are subscribed to Oracle security update notification or you check it regularly you will see if and when there is an update should it apply.
michaln
Oracle Corporation
Posts: 2973
Joined: 19. Dec 2007, 15:45
Primary OS: MS Windows 7
VBox Version: VirtualBox+Oracle ExtPack
Guest OSses: Any and all
Contact:

Re: Does this vulnerability affect VirtualBox?

Post by michaln »

Without making any official statement, I would suggest to review the VMware response to this issue, consider the differences between Xen and VMware/VirtualBox, and extrapolate from there.
DNS
Posts: 107
Joined: 2. May 2011, 00:16
Primary OS: MS Windows 7
VBox Version: VirtualBox+Oracle ExtPack
Guest OSses: xp win7

Re: Does this vulnerability affect VirtualBox?

Post by DNS »

Thanks for the heads up Michal :)
Technologov
Volunteer
Posts: 3342
Joined: 10. May 2007, 16:59
Location: Israel

Re: Does this vulnerability affect VirtualBox?

Post by Technologov »

Considering this is an Intel CPU bug, I expect Intel to fix it in firmware or BIOS update.
Post Reply