Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-17429

Опубликовано: 07 окт. 2025
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2025-17429: open-vm-tools security update (IMPORTANT)

[12.5.0-1.0.1.el10_0.1]

  • Fix spaces in vmware udev rule for scsi devices [Orabug: 24461968]
  • Fix vmware udev rule in 99-vmware-scsi-timeout.rules file. [Orabug: 22815019]
  • Increase timeout for scsi devices on VMWare guests by adding a udev rule. [Orabug: 21819156]

[12.5.0-1.el10_0.1]

  • ovt-Address-CVE-2025-41244.patch [RHEL-117381]
  • Resolves: RHEL-117381 ([CISA Major Incident] CVE-2025-41244 open-vm-tools: Local privilege escalation in open-vm-tools [rhel-10.0.z])

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

open-vm-tools

12.5.0-1.0.1.el10_0.1

open-vm-tools-desktop

12.5.0-1.0.1.el10_0.1

open-vm-tools-test

12.5.0-1.0.1.el10_0.1

Oracle Linux x86_64

open-vm-tools

12.5.0-1.0.1.el10_0.1

open-vm-tools-desktop

12.5.0-1.0.1.el10_0.1

open-vm-tools-salt-minion

12.5.0-1.0.1.el10_0.1

open-vm-tools-sdmp

12.5.0-1.0.1.el10_0.1

open-vm-tools-test

12.5.0-1.0.1.el10_0.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 1 месяца назад

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

CVSS3: 7.8
nvd
около 1 месяца назад

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

CVSS3: 7.8
debian
около 1 месяца назад

VMware Aria Operations and VMware Tools contain a local privilege esca ...

suse-cvrf
26 дней назад

Security update for open-vm-tools

suse-cvrf
28 дней назад

Security update for open-vm-tools