CVE-2026-71114: Oracle VirtualBox VirtioSCSI Out‑Of‑Bounds Read Information Disclosure Vulnerability
What It Is — Oracle VirtualBox’s VirtioSCSI device driver fails to validate user‑supplied data, allowing a local out‑of‑bounds read. An attacker who can run high‑privileged code inside a guest VM may read memory from the hypervisor.
Exploitability — Requires local code execution with high privileges on the guest; no public exploit code is known. CVSS 6.1 (AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L).
Affected Products — Oracle VirtualBox (all versions prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous vulnerability management and timely patch deployment as evidence of a robust control environment.
- Provides a concrete audit trail: patch status, version inventory, and monitoring logs become defensible proof of due diligence.
- Highlights the importance of secure configuration controls that span host, guest, and hypervisor layers—an area scrutinized by many enterprise buyers.
Recommended Actions
- Inventory all VirtualBox installations and record current version numbers.
- Deploy Oracle’s September 2026 security update to all affected hosts without delay.
- Capture patch‑application evidence (e.g., signed logs, configuration snapshots) in your control repository.
- Enable host‑based monitoring for anomalous VirtioSCSI activity to detect attempted exploitation.
Source: Zero Day Initiative advisory – ZDI‑26‑641 (CVE‑2026‑71114)