CVE-2026-77178: n/a
Description
Oracle VM VirtualBox versions prior to 7.2.8 contain a vulnerability in the PCNet network device model where guest OS users can trigger an out-of-bounds write in the host OS. This issue occurs in the pcnetReceiveNoSync function within DevPCNet.cpp. The vulnerability could potentially allow guest OS users to affect the host OS memory integrity.
CVSS v3.1
Score 9.1critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-77178 describes an out-of-bounds write vulnerability in Oracle VM VirtualBox before version 7.2.8. The flaw exists in the PCNet (Am79C970A) network device model, specifically in the pcnetReceiveNoSync function in DevPCNet.cpp. This vulnerability allows a user operating within a guest OS to cause an out-of-bounds write in the host OS, which could lead to memory corruption or other unintended behavior on the host system.
Potential Impact
The vulnerability allows guest OS users to perform an out-of-bounds write on the host OS memory, which could compromise host system stability or security. However, no information about active exploitation or specific impact scenarios is provided.
Mitigation Recommendations
A fix is available in Oracle VM VirtualBox version 7.2.8. Users should upgrade to version 7.2.8 or later to remediate this vulnerability. No additional mitigation guidance is provided.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-65c9-4f8q-72qc
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-77178"]
- State
- PUBLISHED
Threat ID: 6ac523702cdf04f656c4bf1c
Added to database: 10/06/2026, 16:36:00 UTC
Last enriched: 10/06/2026, 16:49:31 UTC
Last updated: 10/06/2026, 20:48:07 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.