CNNVD-202601-3091 Information

CNNVD ID

CNNVD-202601-3091

CVE-2026-21981

  • CNNVD Published: 2026-01-20

Description (Chinese)

Oracle Virtualization是美国甲骨文(Oracle)公司的一套虚拟化解决方案。该产品用于统一管理从应用程序到磁盘的整个硬件和软件体系,可实现从桌面到数据中心的虚拟化。 Oracle Virtualization的Oracle VM VirtualBox 7.1.14版本和7.2.4版本存在安全漏洞,该漏洞源于高权限攻击者可在执行基础设施上登录进行攻击,可能导致未经授权读取部分数据以及造成部分拒绝服务。

Description (English)

Oracle Virtualization is a virtual solution for Oracle. The product is used for the integrated management of the entire hardware and software system from the application to the disk, with virtualization from the desktop to the data centre. There is a security loophole in Oracle VM VirtualBox version 7.1.14 and version 7.2.4 of Oracle Virtualization, which stems from the fact that high-authority assailants can log in on the implementation infrastructure to attack, which may lead to unauthorized access to part of the data and to partial denial of services.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

甲骨文

Published

2026-01-20

Last Modified

2026-02-24

References

https://access.redhat.com/security/cve/cve-2026-21981 https://www.oracle.com/security-alerts/cpujan2026.html

Patch

https://www.oracle.com/security-alerts/cpujan2026.html

Share on: