Executive brief
Oracle VM VirtualBox is a virtualization platform used to run virtual machines on enterprise and desktop systems. A vulnerability in its Core component allows a high-privileged local user to cause the virtualization service to hang or crash repeatedly, resulting in complete loss of availability for all virtual machines running on the affected host. The impact extends beyond VirtualBox itself to any applications or services dependent on those virtual machines.
Technical details
This is a denial-of-service (DoS) vulnerability in the Core component of Oracle VM VirtualBox. The vulnerability requires high-level privileges and local access to the infrastructure where VirtualBox is running (no network exploitation). An authenticated high-privileged attacker can trigger a hang or repeatedly crash the VirtualBox process, causing complete unavailability. The scope is marked as "changed," indicating that while the vulnerability exists in VirtualBox, successful exploitation can impact other systems or applications relying on the virtual machines. A patch is expected in Oracle's regular security update cycle.
Affected products
- Oracle VM VirtualBox 7.2.14
Timeline
- 2026-08-18: disclosed