ZDI-CAN-31625: ZDI-26-640: Oracle VirtualBox VirtioSCSI Uninitialized Memory Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-71132.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Affected Oracle VirtualBox installations using VirtioSCSI are exposed when an attacker can execute high-privileged code in the target guest system. The issue is an information disclosure vulnerability affecting the local virtualization environment.
What level of access does an attacker need to exploit it?
The attacker must first obtain the ability to execute high-privileged code on the target guest system. The provided information does not describe exploitation by an unauthenticated or remote attacker.