Bug 34641 - open-vm-tools new security issue CVE-2025-41244
Summary: open-vm-tools new security issue CVE-2025-41244
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-10-07 16:12 CEST by Nicolas Salguero
Modified: 2025-10-11 08:19 CEST (History)
6 users (show)

See Also:
Source RPM: open-vm-tools-12.5.2-2.mga10.src.rpm, open-vm-tools-12.3.5-2.1.mga9.src.rpm
CVE: CVE-2025-41244
Status comment: Patch available from upstream


Attachments

Nicolas Salguero 2025-10-07 16:13:34 CEST

CVE: (none) => CVE-2025-41244
Whiteboard: (none) => MGA9TOO
Source RPM: (none) => open-vm-tools-12.5.2-2.mga10.src.rpm, open-vm-tools-12.3.5-2.1.mga9.src.rpm
Status comment: (none) => Patch available from upstream

Comment 1 Marja Van Waes 2025-10-07 19:19:12 CEST
Assigning to the registered maintainer, but CC'ing all, because the registered maintainer seems unavailable

CC: (none) => marja11, pkg-bugs
Assignee: bugsquad => luigiwalser

Comment 2 Mike Rambo 2025-10-08 22:39:15 CEST
Cauldron fixed in open-vm-tools-12.5.2-3.mga10



Package patched for Mageia 9


Advisory:
========================

Patched open-vm-tools package fixes security vulnerability:

It was discovered that open-vm-tools contains a local privilege escalation
vulnerability. A malicious actor with non-administrative privileges on a guest VM may exploit this vulnerability to escalate privileges to root on the same
VM (CVE-2025-41244).


References:
https://www.openwall.com/lists/oss-security/2025/09/29/10
https://www.cve.org/CVERecord?id=CVE-2025-41244
========================

Updated packages in core/updates_testing:
========================
open-vm-tools-12.3.5-2.2.mga9.x86_64.rpm
open-vm-tools-desktop-12.3.5-2.2.mga9.x86_64.rpm
open-vm-tools-devel-12.3.5-2.2.mga9.x86_64.rpm
open-vm-tools-salt-minion-12.3.5-2.2.mga9.x86_64.rpm
open-vm-tools-sdmp-12.3.5-2.2.mga9.x86_64.rpm
open-vm-tools-test-12.3.5-2.2.mga9.x86_64.rpm

from open-vm-tools-12.3.5-2.2.mga9.src.rpm

Assignee: luigiwalser => qa-bugs
Version: Cauldron => 9
CC: (none) => mhrambo3501
Whiteboard: MGA9TOO => (none)

Comment 3 Herman Viaene 2025-10-09 16:47:35 CEST
MGA9-64 Plasma Wayland on Compaq H000SB
No installation issues.
Ref bug 32454, OK on clean install.

Whiteboard: (none) => MGA9-64-OK
CC: (none) => herman.viaene

katnatek 2025-10-09 20:06:05 CEST

Keywords: (none) => advisory

Comment 4 Thomas Andrews 2025-10-11 01:34:54 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 5 Mageia Robot 2025-10-11 08:19:20 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0237.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.