Bug 1212334 - open-vm-tools version 12.2.5 has been released - please rebase
Summary: open-vm-tools version 12.2.5 has been released - please rebase
Status: RESOLVED WONTFIX
Alias: None
Product: openSUSE Tumbleweed
Classification: openSUSE
Component: Virtualization:Tools (show other bugs)
Version: Current
Hardware: Other Other
: P5 - None : Normal (vote)
Target Milestone: ---
Assignee: Kirk Allan
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-06-13 23:03 UTC by John Wolfe
Modified: 2023-07-10 15:54 UTC (History)
5 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Wolfe 2023-06-13 23:03:10 UTC
open-vm-tools 12.2.5 was released on June 13, 2023.

There are no new features in the open-vm-tools 12.2.5 release. This is primarily a maintenance release that addresses a single critical problem:

  *  Address CVE-2023-20867 announced in https://www.vmware.com/security/advisories/VMSA-2023-0013.html

For complete details, see: https://github.com/vmware/open-vm-tools/releases/tag/stable-12.2.5

Release Notes are available at: https://github.com/vmware/open-vm-tools/blob/stable-12.2.5/ReleaseNotes.md

The granular changes that have gone into the 12.2.5 release are in the ChangeLog at: https://github.com/vmware/open-vm-tools/blob/stable-12.2.5/open-vm-tools/ChangeLog

Patches applicable to previous open-vm-tools releases are available at https://github.com/vmware/open-vm-tools/tree/CVE-2023-20867.patch

Please rebase open-vm-tools version 12.2.5 in supported releases of SLE 12 and 15 for x86_64/amd64 and aarch64/ARM64 architectures as appropriate.
Comment 1 Kirk Allan 2023-07-10 15:54:29 UTC
The CVE patch for CVE-2023-20867 was applied to open-vm-tools 12.2.0 and is now available in the update channels.  See bug 1212143.

As such we will skip this version as its only update is the CVE patch.

Marking as won't fix.