HPE SimpliVity
1821055 Members
2366 Online
109631 Solutions
New Discussion

CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226

 
ldd11000
Senior Member

CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226

Hi,

these CVE are fixed by vmware with ESXi80U3d-24585383

Do you think HPE will provide the ESXi80U3d-24585383 bundle quickly?

 

12 REPLIES 12
Jarvisstark01
Advisor

Re: CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226

HPE typically releases customized ESXi images promptly after VMware's updates. For the latest information on the availability of the ESXi80U3d-24585383 bundle, please visit HPE's VMware ESXi page.

Kipp_Glover
HPE Pro

Re: CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226

Update:   We have a target date of the end of April to release custom ESXi bundles for 7.0U3s & 8.0U3d along with a new catalog file.  Once these are released, a customer can use Upgrade Manager to apply these patches.

Note:  This is a target date and may change.  I will post an update if this date changes.  

/Kipp



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
BaSe1
Occasional Advisor

Re: CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226

How quickly is the PDF updated after the VMware Critical Patches are released? I am urgently waiting for it.

https://vibsdepot.hpe.com/customimages/Valid-vLCM-Combos.pdf

MarioE
Trusted Contributor

Re: CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226

I have opened a case with HPE. Statement from support:

   Currently the versions ESXi 7.0U3s  and 8.0U3d are undergoing tests with SimpliVity. They are expected to be officially released on 30th of April.

1½ months for a critical patch...

ErwinH
Frequent Advisor

Re: CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226

Hi Kipp,

Normally HPE is much faster with releasing security updates, especially the last year and a half. Why does this update, from 8.0U3c to 8.0U3d take another month and a half to release?

Kind regards,
Erwin

Kipp_Glover
HPE Pro

Re: CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226

Hi Erwin!

If you cannot wait for the custom SimpliVity ESXi bundle, you can source the patch directly from Broadcom and install it via esxcli.  HPE will support the patch.  The Interop Guide will not be updated until the custom SimpliVity ESXi bundle is published at the end of April.  

We normally have a two-month cycle in which we publish new SimpliVity ESXi Custom Bundles and SVTSP firmware bundles.  These recent patches from Broadcom came as we were nearing the end of our cycle.  To properly build and qualify the bundles, we had to push the release to the end of April.  I am sorry for the delay. 

Cheers!
/Kipp



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
Kipp_Glover
HPE Pro

Re: CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226

Today a Customer Notice was published:  https://support.hpe.com/hpesc/public/docDisplay?docId=emr_na-a00146320en_us

/Kipp



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
ErwinH
Frequent Advisor

Re: CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226

Good morning Kipp,

Thanks for the quick response. Good to hear that the update can be installed!

Kind regards,
Erwin

Rashad2
Visitor

Re: CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226

any good news regarding the custom image.

Kipp_Glover
HPE Pro

Re: CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226

Hi Rashad2!

The current plan is to publish both SimpliVity custom bundles, ESXi 8.0 U3d & ESXi 7.0 U3s, on Monday April 28th.  This may change and I will let you know if it does.  

Cheers!
/Kipp



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
Kipp_Glover
HPE Pro

Re: CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226

** JUST RELEASED TODAY ** Two new SimpliVity Custom ESXi offline bundles along with the necessary Interop Catalog file are available for download.
The customer notice will be published later today, and the link will be added to this thread.


I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
Rashad2
Visitor

Re: CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226

thanks @Kipp_Glover 
Also is there any news regarding synergy image release date?