SUSE-SU-2022:2961-1

    Dashboard / Vulnerabilities / SUSE-SU-2022:2961-1

    SUSE-SU-2022:2961-1

    Published: 31 Aug 2022Last Modified: 2 May 2025
    Upstream:

    Summary: Security update for open-vm-tools

    Details: This update for open-vm-tools fixes the following issues: - CVE-2022-31676: Fixed an issue that could allow unprivileged users inside a virtual machine to escalate privileges (bsc#1202657). Non-security fixes: - Update to 11.0.5 (build 15389592) (bsc#1165955) DNS server is reported incorrectly in GuestInfo as '127.0.0.53', when the OS uses systemd-resolved. This issue is fixed in this release. Added Application Discover (appInfo) plugin. The plugin collects the information about running applications inside the guest and publishes the information to a guest variable. - GCC-10 compiler failure (bsc#1160408) The update will solve a GNU compiler Collection GCC10 failure with -fno-common. - Rectify a log spew in vmsvc logging (bsc#1162435, bsc#1162119) When a LSI Logic Parallel SCSI controller sits in PCI bus 0 (SCSI controller 0), the Linux disk device enumeration does not provide a 'label' file with the controller name. This results in messages like 'GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for '/var/log', fsName: '/dev/sda2' repeatedly appearing in the vmsvc logging. The update converts what previously was a warning message to a debug message and thus avoids the log spew.

    Affected packages

    Package

    Name: open-vm-tools

    Purl: pkg:rpm/suse/open-vm-tools&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOS

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -11.0.5-150000.3.29.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2022:2961-1 | CVE-DB