Knowledge Base

Search the Knowledge Base: |
Search the Knowledge Base: |
VMware ESXi 3.5, Patch ESXe350-200809401-I-SG: Firmware Update
Details
Release Date: 03-Oct-2008
Document Last Updated: 03-Oct-2008
|
Download Size: 203MB Download Filename: ESXe350-200809401-O-SG.zip md5sum: 0eadf92eaf0d721e63200348a53e0469 Note: The three ESXi patches for Firmware "I", VMware Tools "T," and the VI Client "C" are contained in a single offline "O" download file. |
|
Solution
Summaries and Symptoms
This patch fixes the following issues:
-
VMware addresses an in-guest privilege escalation on 64-bit guest operating systems.
VMware products emulate hardware functions including CPU, memory, and I/O.
A flaw in VMware's CPU hardware emulation could allow the virtual CPU to jump to an incorrect memory address. Exploitation of this issue on the guest operating system does not lead to a compromise of the host system, but could lead to a privilege escalation on guest operating systems. An attacker would need to have a user account on the guest operating system.
Affected guest operating systems include 64-bit Windows, 64-bit FreeBSD, and possibly other 64-bit operating systems.
The issue does not affect the 64-bit versions of Linux guest operating systems.
VMware would like to thank Derek Soeder for discovering this issue and working with us on its remediation.
The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2008-4279 this issue.
- VI Client shows host as not responding during HA-DRS cluster operations.
During HA-DRS cluster operations like adding or removing a host from a DRS cluster or applying DRS recommendations, the VI Client might show the host as "Not responding," even when the host IP can be reached.
Note: This patch in conjunction with VirtualCenter 2.5 Update 3 (upcoming release) provides a full resolution to this issue.
- VMware has identified an issue on systems with AMD Barcelona processors running ESX/ESXi 3.5 Update 1 or Update 2. While performing a VMotion from or to one of these systems, the virtual machine might fail to respond with the following symptoms:
- Virtual machines running Microsoft 64-bit Windows operating systems might crash (blue screen) with the message: mfehidk.sys PAGE_FAULT_IN_NONPAGED_AREA.
- Virtual machines running Linux 64-bit operating systems might experience a panic.
Note: Some customers have seen this behavior using anti-virus software in the previously-mentioned environments.
For a full description of this problem and its pre-patch workaround, see http://kb.vmware.com/kb/1007072.
- Virtual machines running Microsoft 64-bit Windows operating systems might crash (blue screen) with the message: mfehidk.sys PAGE_FAULT_IN_NONPAGED_AREA.
Deployment Considerations
None beyond the required patch bundles and reboot information listed in the table, above.
Patch Download and Installation
The typical way to apply patches to ESXi hosts is through the VMware Update Manager. For details, see the VMware Update Manager Administration Guide.
ESXi hosts can also be updated by downloading the most recent "O" (offline) patch bundle from http://support.vmware.com/selfsupport/download/ and installing the bundle using VMware Infrastructure Update or by using the vihostupdate command through the Remote Command Line Interface (RCLI). For details, see the ESX Server 3i Configuration Guide and the ESX Server 3i Embedded Setup Guide (Chapter 10, Maintaining ESX Server 3i and the VI Client) or the ESX Server 3i Installable Setup Guide (Chapter 11, Maintaining ESX Server 3i and the VI Client).
Note: ESXi hosts do not reboot automatically when you patch with the offline bundle.
Feedback
- KB Article: 1007090
- Updated: Aug 14, 2009
- Products:
VMware ESXi - Product Versions:
VMware ESXi 3.5.x Embedded
VMware ESXi 3.5.x Installable

