This bug was fixed in the package open-vm-tools -
2:13.0.0-2~ubuntu0.24.04.1

---------------
open-vm-tools (2:13.0.0-2~ubuntu0.24.04.1) noble; urgency=medium

  * Backport recent open-vm-tools release v13.0.0 (LP: #2127666)
    - For changes included in this update, see:
      https://github.com/vmware/open-vm-tools/blob/stable-13.0.0/ReleaseNotes.md

open-vm-tools (2:13.0.0-2ubuntu1) questing; urgency=medium

  * SECURITY UPDATE: local privilege escalation in Service Discovery Plugin
    - debian/patches/CVE-2025-41244.patch: disable by default the execution
      of the SDMP get-versions.sh script in
      open-vm-tools/services/plugins/serviceDiscovery/serviceDiscovery.c.
    - CVE-2025-41244

open-vm-tools (2:13.0.0-2) unstable; urgency=medium

  * Upload to unstable.

open-vm-tools (2:13.0.0-1) experimental; urgency=medium

  * [6e2779c] Refreshing patches.
    Dropping patches applied upstream
  * [209b17e] Add libcrypt-dev to Build-Depends. (Closes: #1106954)
  * [2f26698] New upstream version 13.0.0

open-vm-tools (2:12.5.0-2) unstable; urgency=high

  * [910f279] Fixing an insecure file handling vulnerability.
    It allowed a malicious actor with non-administrative privileges
    on a guest VM to tamper the local files to trigger insecure file
    operations within that VM.
    VMSA-2025-0007
    CVE-2025-22247 (Closes: #1105159)

 -- Renan Rodrigo <[email protected]>  Wed, 25 Mar 2026 16:34:10 -0300

** Changed in: open-vm-tools (Ubuntu Noble)
       Status: Fix Committed => Fix Released

** CVE added: https://cve.org/CVERecord?id=CVE-2025-22247

** CVE added: https://cve.org/CVERecord?id=CVE-2025-41244

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2127666

Title:
  Backport of open-vm-tools for noble

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/open-vm-tools/+bug/2127666/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to