When I performed upgrade-nonroot , I noticed that virtualbox guest x11 packages were automatically removed. After I restarted my Whonix machine, I lost an ability to resize screen. How to fix it?
The latest upgrade replaced virtualbox-guest-x11 and virtualbox-guest-utils packages with dist-vm-gui-all and whonix-gateway-vm-gui-lxqt which don’t work in VirtualBox 7.0. Dear Whonix developers, I guess breaking a working system is not a good idea. Not everyone is able to upgrade from VirtualBox 7.0 to newer versions of VirtualBox.
Is it safe to remove dist-vm-gui-all and whonix-gateway-vm-gui-lxqt and install virtualbox-guest-x11 and virtualbox-guest-utils back?
No, do not do this. It will break your ability to upgrade your system properly in the future.
The way Guest Additions are installed was changed to support clipboard sharing, but there is a known bug where the old Guest Additions can sometimes get uninstalled without installing the new ones. To fix this, boot into a sysmaint session and run sudo vbox-guest-installer. This will install Guest Additions, and they should automatically update themselves in the future.
Using Whonix on versions of VirtualBox other than the latest release is not supported for both maintenance and security reasons. If you cannot upgrade to a newer version of VirtualBox, your setup is unsafe and you must resolve whatever is preventing the upgrade to reduce the risk of anonymity leaks and system compromise. (Or alternatively, you could switch to KVM or Qubes OS and keep those up to date if they don’t pose a problem.)
1 Like
It is declared that Whonix is secure by design which should mean no matter what kind of host OS and version of virtualization software you use, it remains secure. Isn’t it true now? Why should I use the latest version of VirtualBox? Previous versions of Whonix did work well on older VirtualBox releases. The design model of Whonix remains the same.
The short answer is no, and it’s never been true that running any OS on an outdated hypervisor is secure.
Longer answer:
The OS is secure by design, so it should hold up much better than other operating systems against attempts to compromise the OS. That will potentially hold true even if the virtualizer is buggy and insecure. But no amount of an OS being secure by design will save you if you, the user, grant administrative powers to malware in the workstation by accident. Once malware gets root privileges (and sometimes even without root privileges), it can attack the virtualizer and compromise the host if the virtualizer is vulnerable. The OS security will not and cannot stop this.
Beyond that, virtualizer bugs could theoretically make secure code behave in an insecure manner even within the VM itself. Thus a vulnerability in the virtualizer could subvert the security of the VM even if the code in the VM is not secure.
Whonix uses the virtualizer as a security boundary. That’s how it can say that it will prevent anonymity leaks even if the workstation is compromised. If your virtualizer isn’t acting as a security boundary, you’re in danger.
This is probably correct for a very outdated version of hypervisor, like VirtualBox 5.x etc. But as for 7.0, it might be still secure since Debian host might provide security updates for it. Many host OS like Debian stable or Debian oldstable don’t have an ability to quickly upgrade VirtualBox to a new major version since their update policy is based on stability not novelty. What can a user do in this case?
VirtualBox is excluded from Debian Stable upstream until further notice, because Oracle makes it impractical to backport security fixes. See:
VirtualBox versions as recent as 7.2.16 have bugs that allow an attacker with sufficient privileges in a VM to achieve arbitrary code execution on the host:
https://www.cve.org/CVERecord?id=CVE-2026-87276
Debian does not include VirtualBox in their stable repositories at all, so this isn’t a problem for them. VirtualBox is in the universe repository of Ubuntu and does not receive security maintenance. I don’t really know how other distros handle it.
Use Oracle’s VirtualBox repository. This will provide the most recent version of VirtualBox on various Linux platforms, including Debian. Kicksecure’s virtualbox-installer-cli script will install VirtualBox using that repository, and it will update to the latest version within a major branch as part of normal software updates. (Manual installation of newer major branches, like VirtualBox 7.3 when it comes out, is still necessary when doing this.)