VMware
 

Knowledge Base

Search the Knowledge Base:

Products:
Search In:
 

VMware ESX Server 3.0.3, ESX303-200809401-SG: Security and Other Fixes for VMware-esx-vmx, VMware-esx-vmkernel, and VMware-hostd-esx RPMs

Details

Release Date: 09/30/08
Document Last Updated: 10/6/08
 

131 MB
Download Filename:
ESX303-200809401-SG.zip
md5sum:
e3be0f0f0b8a3ae612d99db2fa79c9e8


 
Product Versions ESX Server 3.0.3
Patch Classification Security
Supersedes ESX303-200808403-SG, ESX303-200808404-SG
Requires None
Virtual Machine Migration or Reboot Required Yes
ESX Server Host Reboot Required Yes
PRs Fixed 157117, 296333, 302726, 193839
Affected Hardware N/A
Affected Software Virtual E1000 NIC, Guest operating systems: 64-bit Windows, 64-bit FreeBSD
RPMs Included VMware-esx-vmx, VMware-esx-vmkernel, VMware-hostd-esx
Related CVE numbers CVE-2008-4279

Solution

Summaries and Symptoms

This patch fixes the following issues:
  • Guest operating systems generate host bus adapters warnings in the recent Linux kernels containing the ata_piix4 driver. Hard disks and CD-ROM drives are not recognized.
  • When using the virtual E1000 NIC, sometimes the vmkernel might try accessing pages beyond the physical memory range of the guest operating systems, causing the virtual E1000 NIC to stop responding.
     
    Symptom: In a corner case, network service might stop on 64-bit guest operating systems using a virtual E1000 NIC with the following message logged in vmkernel:
    WARNING: Alloc: 3412: vm 1212: ppn=0xc0000 out of range: 0x0-0xc0000 (count=2)
    WARNING: P2MCache: vm 1212: 478: GetPhysMemRange failed: PPN 0xc0000 canBlock 0 status Bad parameter
  • Any user running an info-get command with an invalid key in the guest operating system might cause the virtual machine to stop responding. The info-get command run on Windows operating systems is VMwareService -cmd "info-get". The info-get command run on Linux operating systems is vmware-guestd --cmd "info-get".
  • The range track overflows and triggers flushing of all dependent translation look-aside buffers (TLBs) causing serious performance impact. 

  • VMware addresses an in-guest privilege escalation on 64-bit guest operating systems.

    VMware products emulate hardware functions including CPU, memory, and I/O.

    A flaw in VMware's CPU hardware emulation could allow the virtual CPU to jump to an incorrect memory address. Exploitation of this issue on the guest operating system does not lead to a compromise of the host system, but could lead to a privilege escalation on guest operating systems. An attacker would need to have a user account on the guest operating system.

    Affected guest operating systems include 64-bit Windows, 64-bit FreeBSD, and possibly other 64-bit operating systems.

    The issue does not affect the 64-bit versions of Linux guest operating systems.

    VMware would like to thank Derek Soeder for discovering this issue and working with us on its remediation.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2008-4279 this issue.

Deployment Considerations

None beyond the required patch bundles and reboot information listed in the table, above.

Patch Download and Installation

Note: All virtual machines on the host must be either shut down or migrated using VMotion before applying the patch. A reboot of the ESX Server host is required after applying this patch.
 
See the VMware Update Manager Administration Guide for instructions on using VMware Update Manager to download and install patches to automatically update ESX Server 3.0.3 hosts.

To update ESX Server 3.0.3 hosts when not using VMware Update Manager, download the most recent patch bundle from http://support.vmware.com/selfsupport/download/ and install the bundle using esxupdate from the command line of the host. For more information, see the ESX Server 3 Patch Management Guide .

Keywords

esxpatch;esx303

Feedback

Rating: 1 - Lowest 2 3 4 5 - Highest (0 Ratings)   

Did this article help you?
This article resolved my issue.
This article did not resolve my issue.
This article helped but additional information was required to resolve my issue.
What can we do to improve this information? (2000 or fewer characters)
Submit
Rating: 1 - Lowest 2 3 4 5 - Highest (0 Ratings)   
Actions