CVE-2021-25319 PUBLISHED

A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.

EPSS 0.02% · 6.5th percentile

Risk Scores

EPSS Score
0.02%
6.5th percentile

Affected Products

VendorProductVersions
Ubuntu:25.10virtualbox7.1.10-dfsg-1, 7.1.12-dfsg-1, 7.1.12-dfsg-2
Ubuntu:24.04:LTSvirtualbox7.0.14-dfsg-4build4, 7.0.14-dfsg-4, 7.0.14-dfsg-2
Ubuntu:20.04:LTSvirtualbox6.1.22-dfsg-2~ubuntu1.20.04.1, 6.1.26-dfsg-3~ubuntu1.20.04.1, 6.1.38-dfsg-3~ubuntu1.20.04.1
Ubuntu:16.04:LTSvirtualbox*, 5.0.4-dfsg-2, 5.0.8-dfsg-1
Ubuntu:22.04:LTSvirtualbox6.1.32-dfsg-1build1, *, *
Ubuntu:18.04:LTSvirtualbox5.2.10-dfsg-2, 5.2.10-dfsg-1, 5.2.8-dfsg-7

Timeline

References

Open in Interactive Console →