Sceawere

Vulnerability Detail

CVE-2026-77178UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

VirtualBox PCNet Out-of-Bounds Write

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
11h ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Oracle VM VirtualBox before 7.2.8 allows guest OS users to cause an out-of-bounds write in the host OS in pcnetReceiveNoSync in DevPCNet.cpp in the PCNet (Am79C970A) network device model.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-10-06T14:17:46.250Z",
  "pubdate": "2026-10-06T14:17:46.250Z",
  "executiveSummary": "Oracle VM VirtualBox versions prior to 7.2.8 are susceptible to a critical out-of-bounds (OOB) write vulnerability located within the PCNet (Am79C970A) network device model.\nThis vulnerability originates in the pcnetReceiveNoSync function within the DevPCNet.cpp source file. An attacker with guest OS access can leverage this flaw to trigger memory corruption on the host system.\nSuccessful exploitation allows a malicious guest user to write data outside the intended bounds of the allocated buffer, potentially leading to arbitrary code execution, host system compromise, or a complete denial-of-service (DoS) condition by crashing the VirtualBox process.\nThis vulnerability is particularly dangerous as it represents a guest-to-host breakout vector. Attackers require active guest OS access to interact with the emulated network hardware, but no additional privileges beyond the ability to manipulate device registers are typically required to initiate the attack flow.",
  "technicalDetails": "The vulnerability resides in the emulation logic of the AMD Am79C970A PCnet-PCI Ethernet controller provided by VirtualBox. Specifically, the pcnetReceiveNoSync function in DevPCNet.cpp fails to adequately validate the bounds of incoming network traffic or associated descriptor ring state during the packet reception process.\nThe root cause is an insufficient boundary check during the transfer of data from the emulated network interface into the host's memory space. When the guest OS programs the device to receive frames, it influences the configuration of the descriptor rings and associated buffer pointers. If an attacker intentionally crafts malicious descriptors or manipulates the PCNet hardware registers to supply an invalid length or offset, the pcnetReceiveNoSync function may perform memory operations beyond the intended heap buffer allocated for the emulated device.\nAttack flow typically begins with the guest OS initializing the PCNet network driver. The attacker sends specially crafted frames or manipulates the transmit/receive descriptor rings in memory to trigger a scenario where the internal state machine of the PCNet model miscalculates the required buffer size. Because the emulation layer operates with the permissions of the host process running the virtual machine, the resulting out-of-bounds write occurs within the context of the host's memory space.\nThe OOB write allows the attacker to overwrite adjacent memory structures in the VirtualBox process. By precisely controlling the data written out-of-bounds, an attacker might overwrite function pointers, object vtables, or sensitive heap metadata. This control can be leveraged to divert execution flow, effectively bypassing guest isolation mechanisms and achieving execution of arbitrary code with the privilege level of the VirtualBox process on the host operating system.\nThis vulnerability is categorized as a memory corruption flaw, specifically an out-of-bounds write. It affects all virtual machines configured to utilize the PCNet-PCI network adapter emulation in affected Oracle VM VirtualBox versions prior to 7.2.8. No specific network exposure is required beyond the guest's ability to communicate with the virtualized network device, and the attack does not depend on external network traffic, making it a purely local guest-to-host exploitation vector."
}
CVE-2026-77178: VirtualBox PCNet Out-of-Bounds Write (CRITICAL Severity, CVSS: 9.1) | Sceawere