SUSE-SU-2022:2961-1
Dashboard / Vulnerabilities / SUSE-SU-2022:2961-1
SUSE-SU-2022:2961-1
Summary: Security update for open-vm-tools
Details: This update for open-vm-tools fixes the following issues: - CVE-2022-31676: Fixed an issue that could allow unprivileged users inside a virtual machine to escalate privileges (bsc#1202657). Non-security fixes: - Update to 11.0.5 (build 15389592) (bsc#1165955) DNS server is reported incorrectly in GuestInfo as '127.0.0.53', when the OS uses systemd-resolved. This issue is fixed in this release. Added Application Discover (appInfo) plugin. The plugin collects the information about running applications inside the guest and publishes the information to a guest variable. - GCC-10 compiler failure (bsc#1160408) The update will solve a GNU compiler Collection GCC10 failure with -fno-common. - Rectify a log spew in vmsvc logging (bsc#1162435, bsc#1162119) When a LSI Logic Parallel SCSI controller sits in PCI bus 0 (SCSI controller 0), the Linux disk device enumeration does not provide a 'label' file with the controller name. This results in messages like 'GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for '/var/log', fsName: '/dev/sda2' repeatedly appearing in the vmsvc logging. The update converts what previously was a warning message to a debug message and thus avoids the log spew.
References: https://www.suse.com/support/update/announcement/2022/suse-su-20222961-1/, https://bugzilla.suse.com/1160408, https://bugzilla.suse.com/1162119, https://bugzilla.suse.com/1162435, https://bugzilla.suse.com/1165955, https://bugzilla.suse.com/1202657, https://www.suse.com/security/cve/CVE-2022-31676
Affected packages
Package
Name: open-vm-tools
Purl: pkg:rpm/suse/open-vm-tools&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOS
Affected ranges
Type: ECOSYSTEM
Events:
