VM escape vulnerabilities patched in VirtualBox
techrepublic.com
techrepublic.com
Edit: The first sentence:
> Oracle has released patches for ten vulnerabilities in VirtualBox which allow attackers to break out of guest operating systems and attack the host operating system that VirtualBox runs on.
And at http://www.oracle.com/technetwork/security-advisory/cpujan20...
> Supported Versions Affected ... Prior to 5.1.32, Prior to 5.2.6
The current version being 5.2.6
When they acquired Sun, they seemed in a hurry to kill off all the other open source projects Sun had been running.
Do they use it as the basis for their cloud-infrastructure[1] or what? I do not see how VirtualBox generates any revenue for Oracle, and they have a reputation for being very ... focussed when it comes to revenue.
[1] That seems pretty unlikely
https://www.npr.org/sections/money/2012/08/01/157743897/can-...
Patent Troll: Hi, I am a Patent Troll,
and I want to sue your ... company.
Halliburton: Look, Dame or Dude, you have three choices:
1. We have a patent on that.
You cannot sue us without a license.
Good bye!
2. We have a patent on that.
You cannot sue us without a license.
Licenses are $ 42 trillion.
*Per Lawyer*.
See you in court. Or not.
3. We buy your company, because we rule!
Patent Troll: *Head explodes*
-- The End --
A decent writer could make a sitcom out of this in no time. I already have a picture in my head -- it is like Night Court meets Psych! I wanna watch this on Netflix!!![1]: https://shop.oracle.com/apex/product?p1=OracleVMVirtualBoxEn...
However, even the extensions used to be free for "noncommercial use in a commercial environment" --- they silently changed the license relatively recently: https://forums.virtualbox.org/viewtopic.php?f=1&t=85092
I guess I'm going to have to switch to using KVM at work now if I to do things like USB device passthrough now. Shame too because setting up KVM networking is way more complicated than setting up VirtualBox networking.
Any other hypervisor. QEMU/KVM, Xen, VMWare, and Parallels all have good track records.
This skews the CVE stats significantly since the kernel developers (aka kvm) rarely actually request CVE ids.
On Windows, there is Hyper-V. I have only very little experience with it, but in my short time, I did not encounter anything I would like to complain about. I am not sure, however, if it comes with the client editions of Windows. Microsoft Virtual PC still exists, too.
Xen is also a thing - run Dom0 as your desktop system, and run the VMs in the background.
None of this is perfect, but if you need them, there are alternatives.
Not updated in almost 10 years, not supported on Windows 8 or 10.
It's in Windows 10 client editions too. Look under "Turn Windows features on or off". Windows Subsystem for Linux is there too.
AWS recently started moving from a custom Xen to a custom KVM, but it doesn't seem it was for security reasons. Xen certainly is heavily used by public cloud providers.
Because of its use with KVM, QEMU has had its code scrutinized quite closely in the last few years. There are some device models that have a pretty bad track record, such as Cirrus VGA, but they are not the default anymore and there's no reason why you should use them.
https://www.cvedetails.com/vulnerability-list/vendor_id-2505...
Better than this though:
https://www.cvedetails.com/vulnerability-list/vendor_id-93/p...
This is particularly important when KVM is used with a special user (such as user "qemu") and SELinux, because then a bug in QEMU becomes extremely hard to turn into host root access. Libvirt takes care of configuring SELinux this way for you, when you use for example KVM on OpenStack.
This also holds true for the alternatives.
VirtualBox also has a slicker UI compared with QEMU/KVM on linux & bhyve on FreeBSD/Mac & vmm on OpenBSD.
The alternatives all have their own merits, but if people are wondering why anyone would use VirtualBox, I believe the above reasons are why.
I run several VMs at the same time, occasionally one will freeze. I think it's just the video/display that freezes while the browser/whatever in the guest VM still operates normally.
"The vulnerabilities found in the core graphics framework (VBVA subcomponent) and affect all host operating systems."