Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Fedora 42: FEDORA-2025-23653a72d9 critical: open-vm-tools file handling

fedora
Calendar Grey May 20, 2025
Scroller Fedora
Debian release of open-vm-tools 12.5.2 addresses urgent security flaw in file management. Protect your devices immediately!
Update to version 12.5.2

Summary

The open-vm-tools project is an open source implementation of VMware Tools. It

is a suite of open source virtualization utilities and drivers to improve the

functionality, user experience and administration of VMware virtual machines.

This package contains only the core user-space programs and libraries of

open-vm-tools.

Update Information:

Update to version 12.5.2. Fixes CVE-2025-22247

Change Log

* Fri May 16 2025 Simone Caronni - 12.5.2-1 - Update to 12.5.2

References


[ 1 ] Bug #2294721 - open-vm-tools version 12.4.5 has been released - please rebase https://bugzilla.redhat.com/show_bug.cgi?id=2294721 [ 2 ] Bug #2320094 - open-vm-tools version 12.5.0 has been released - please rebase https://bugzilla.redhat.com/show_bug.cgi?id=2320094 [ 3 ] Bug #2365723 - CVE-2025-22247 open-vm-tools: Insecure file handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2365723

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-23653a72d9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: open-vm-tools
Product: Fedora 42
Version: 12.5.2
Release: 1.fc42
Summary: Open Virtual Machine Tools for virtual machines hosted on VMware

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.