VirtualBox 7.2.18 Release

Oracle has published a corrective release of the virtualization system VirtualBox 7.2.18, which introduces 11 changes and fixed 19 vulnerabilities. The most serious problem (CVE-2026-87273) is assigned a severity level of 8.6 out of 10, another 5 problems, of which 4 are specific to Windows, are assigned a severity level of 7.8 out of 10. Judging by the severity level, these vulnerabilities allow access to the host environment from the guest system. Details about the nature of the vulnerabilities are not disclosed.

Non-security changes:

  • Add-ons for guest systems and host environments with Linux now support the kernel package from the RHEL 10.3 distribution.
  • Additions for guest systems with Linux solve problems with assembly on systems with the Linux kernel 6.12.103.
  • Additions for host environments with Linux solve problems with assembly in RHEL 9.8 and on systems with the Linux kernel 7.3-rc, as well as on systems with AMD CPUs that do not have support for the Intel FRED (Flexible Return and Event Delivery) system call optimization mechanism.
  • Fixed a crash in Windows 11 on ARM platforms when restoring a guest system from a saved state.
  • Fixed data corruption in VDI images that occurred when reopening the image after writing zero-filled blocks to it.
  • Fixed a virtual machine crash that occurred in host environments with Linux when 3D acceleration was enabled.
  • In the implementation of the Shared Clipboard, a bug was fixed due to which the first character in the names of files located in the root of the file system was missing when copying.
/Reports, release notes, official announcements.