{"id":"SUSE-SU-2022:2961-1","summary":"Security update for open-vm-tools","details":"This update for open-vm-tools fixes the following issues:\n\n- CVE-2022-31676: Fixed an issue that could allow unprivileged users inside a virtual machine to escalate privileges (bsc#1202657).\n\nNon-security fixes:\n\n- Update to 11.0.5 (build 15389592) (bsc#1165955)\n  DNS server is reported incorrectly in GuestInfo as '127.0.0.53', when\n  the OS uses systemd-resolved. This issue is fixed in this release.\n  Added Application Discover (appInfo) plugin.  \n  The plugin collects the information about running applications inside the guest\n  and publishes the information to a guest variable.\n\n- GCC-10 compiler failure (bsc#1160408)\n  The update will solve a GNU compiler Collection GCC10 failure with -fno-common.\n  \n- Rectify a log spew in vmsvc logging (bsc#1162435, bsc#1162119)\n  When a LSI Logic Parallel SCSI controller sits in PCI bus 0 (SCSI controller 0), the Linux disk device enumeration\n  does not provide a 'label' file with the controller name.  This results in messages like\n  'GuestInfoGetDiskDevice: Missing disk device name; VMDK mapping unavailable for '/var/log', fsName: '/dev/sda2'\n  repeatedly appearing in the vmsvc logging. The update converts what previously was a warning message to a debug\n  message and thus avoids the log spew.\n","modified":"2026-03-11T07:20:40.980924Z","published":"2022-08-31T13:47:19Z","related":["CVE-2022-31676"],"upstream":["CVE-2022-31676"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20222961-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1160408"},{"type":"REPORT","url":"https://bugzilla.suse.com/1162119"},{"type":"REPORT","url":"https://bugzilla.suse.com/1162435"},{"type":"REPORT","url":"https://bugzilla.suse.com/1165955"},{"type":"REPORT","url":"https://bugzilla.suse.com/1202657"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-31676"}],"affected":[{"package":{"name":"open-vm-tools","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15-ESPOS","purl":"pkg:rpm/suse/open-vm-tools&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.0.5-150000.3.29.1"}]}],"ecosystem_specific":{"binaries":[{"libvmtools-devel":"11.0.5-150000.3.29.1","libvmtools0":"11.0.5-150000.3.29.1","open-vm-tools-desktop":"11.0.5-150000.3.29.1","open-vm-tools":"11.0.5-150000.3.29.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:2961-1.json"}},{"package":{"name":"open-vm-tools","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15-LTSS","purl":"pkg:rpm/suse/open-vm-tools&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.0.5-150000.3.29.1"}]}],"ecosystem_specific":{"binaries":[{"libvmtools-devel":"11.0.5-150000.3.29.1","libvmtools0":"11.0.5-150000.3.29.1","open-vm-tools-desktop":"11.0.5-150000.3.29.1","open-vm-tools":"11.0.5-150000.3.29.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:2961-1.json"}},{"package":{"name":"open-vm-tools","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15","purl":"pkg:rpm/suse/open-vm-tools&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.0.5-150000.3.29.1"}]}],"ecosystem_specific":{"binaries":[{"libvmtools-devel":"11.0.5-150000.3.29.1","libvmtools0":"11.0.5-150000.3.29.1","open-vm-tools-desktop":"11.0.5-150000.3.29.1","open-vm-tools":"11.0.5-150000.3.29.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:2961-1.json"}}],"schema_version":"1.7.5"}