CVE-2026-77178 | Oracle VM VirtualBox up to 7.2.7 PCNet Network Device Model DevPCNet.cpp pcnetReceiveNoSync out-of-bounds write

SecurityVulns

A vulnerability described as very critical has been identified in Oracle VM VirtualBox up to 7.2.7. This issue affects the function pcnetReceiveNoSync of the file DevPCNet.cpp of the component PCNet Network Device Model. Executing a manipulation can lead to out-of-bounds write. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is handled as CVE-2026-77178. It is possible to launch the attack on the local host. There is not any exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More