Knowledge Base

|
VMware ESX 4.0, Patch ESX400-201110401-SG: Updates VMkernel, VMX, hostd, VMware Tools (1036392)
Details
Release date: October 13, 2011
| Patch Classification | Security |
| Build | For build information, see KB 1036391. |
| Host Reboot Required | Yes |
| Virtual Machine Migration or Shutdown Required | Yes |
| PRs Fixed | 570658, 654821, 701914, 710561, 711213, 719777, and 730105 |
| Affected Hardware | N/A |
| Affected Software | N/A |
| VIBs Included | vmware-esx-cim, vmware-esx-tools, vmware-esx-uwlibs, vmware-esx-vmkernel64, vmware-esx-vmnixmod, vmware-esx-vmx, vmware-hostd-esx, and kernel |
| Related CVE numbers | CVE-2010-1083, CVE-2010-2492, CVE-2010-2798, CVE-2010-2938, CVE-2010-2942, CVE-2010-2943, CVE-2010-3015, CVE-2010-3904, CVE-2010-3066, CVE-2010-3067, CVE-2010-3078, CVE-2010-3086, CVE-2010-3477, CVE-2010-3432, CVE-2010-3442, CVE-2010-3699, CVE-2010-3858, CVE-2010-3859, CVE-2010-3865, CVE-2010-3876, CVE-2010-3880, CVE-2010-4083, CVE-2010-4157, CVE-2010-4161, CVE-2010-4242, CVE-2010-4247, CVE-2010-4248, CVE-2010-3296, CVE-2010-3877, CVE-2010-4072, CVE-2010-4073, CVE-2010-4075, CVE-2010-4080, CVE-2010-4081, CVE-2010-4158, CVE-2010-4238, CVE-2010-4243, CVE-2010-4255, CVE-2010-4263, CVE-2010-4343, CVE-2010-4526, CVE-2010-4249, CVE-2010-4251, CVE-2010-4655, CVE-2010-4346, CVE-2011-0521, CVE-2011-0710, CVE-2011-1010, CVE-2011-1090, CVE-2011-1478, CVE-2010-0296, CVE-2011-0536, CVE-2011-1071, CVE-2011-1095, CVE-2011-1658, and CVE-2011-1659 |
Solution
Summaries and Symptoms
This patch resolves the following issues:
- Due to exhaustion of VMkernel socket resources on ESX hosts, powering on virtual machines might report some virtual machines in an invalid state, and the messages log might contain entries similar to the following:
sfcb-CIMXML-Processor[9857708]: SendMsg sending to 7 9857708-9 Bad file descriptor
Sfcb-CIMXML-Processor[9857708]: spSendMsg sending to 7 9857708-9 Bad file descriptor
sfcb-CIMXML-Processor[9857708]: --- spSendReq/spSendMsg failed to send on 7 (-1)
root: sfcbd-watchdog:Restarting SFCB! Log a bug!!!
root: sfcbd-watchdog:stopping sfcbd
root: sfcbd Stopping sfcbd
root: sfcbd-watchdog:starting sfcbd
root: sfcbd Starting sfcbd
sfcb-sfcb[9849840]: --- Using /etc/sfcb/sfcb.cfg
FoundryVMDirectlyOpenSocketToVMX: Failed to create socket pair.
For more information about the issue, see KB 1035564.
- Even after you set the devices.hotplug configuration option to false, PCI Express (PCIe) devices are removable.
- When you move a physical NIC that does not support VLAN offload from a vNetwork Distributed Switch (vDS) to a vNetwork Standard Switch (vSS) or from one vDS to another vDS, the ESX host might fail and display a purple diagnostic screen that contains messages similar to:
@BlueScreen: #UD Exception(6) in world 4314:vmm0:AUSD-WC @ 0x41803b9a8763
LBR: from 0x41803b9a8436 to 0x41803b9a8763
Code starts at 0x41803b600000
0x4100c06d7a38:[0x41803b9a8763]process_tx_queue+0x842 stack: 0x100
0x4100c06d7a98:[0x41803b9a8ec1]DevStartTxImmediate+0x198 stack: 0x41000806d580
0x4100c06d7b48:[0x41803b6e21e2]UplinkOutputUnbuffered+0x751 stack: 0x41803b6dc160
0x4100c06d7bb8:[0x41803b6e7025]IOChain_Resume+0x148 stack: 0x4100c06d7c38
0x4100c06d7c38:[0x41803bb78246]TeamES_Output+0x2d9 stack: 0x3c
0x4100c06d7e38:[0x41803bb687aa]EtherswitchPortDispatch+0x16e1 stack: 0x410001004300
0x4100c06d7e68:[0x41803b6d4ec2]Port_Input+0x169 stack: 0x4100c06d7ea8
0x4100c06d7ea8:[0x41803b6d78e6]Portset_ProcessDeferredList+0xb1 stack: 0x410001004360
0x4100c06d7f18:[0x41803b6c4f24]Net_VMMVlanceUpdateMAC+0x3f3 stack: 0x41803b631d4c
0x4100c06d7f98:[0x41803b631c71]VMKCall+0x2bc stack: 0x4100c06d7ff0
0x4100c06d7fe8:[0x41803b68ea9c]VMKVMMEnterVMKernel+0x11f stack: 0x41803b6ab790
This is applicable for VMware vDS and well as third-party vDS.
- When you use VirtualCenter to perform an Open Virtualization Format (OVF) export, virtual machines that have VMXNET 3 network adapters are exported with VMXNET network adapters. Such an export causes virtual machines from this template to be deployed with VMXNET network adapters instead of VMXNET 3 network adapters.
This patch also resolves the following security issues:
- Updates the ESX service console kernel to kernel-2.6.18-238.9.1.el5 and resolves multiple security issues in the service console kernel. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2010-1083, CVE-2010-2492, CVE-2010-2798, CVE-2010-2938, CVE-2010-2942, CVE-2010-2943, CVE-2010-3015, CVE-2010-3904, CVE-2010-3066, CVE-2010-3067, CVE-2010-3078, CVE-2010-3086, CVE-2010-3477, CVE-2010-3432, CVE-2010-3442, CVE-2010-3699, CVE-2010-3858, CVE-2010-3859, CVE-2010-3865, CVE-2010-3876, CVE-2010-3880, CVE-2010-4083, CVE-2010-4157, CVE-2010-4161, CVE-2010-4242, CVE-2010-4247, CVE-2010-4248, CVE-2010-3296, CVE-2010-3877, CVE-2010-4072, CVE-2010-4073, CVE-2010-4075, CVE-2010-4080, CVE-2010-4081, CVE-2010-4158, CVE-2010-4238, CVE-2010-4243, CVE-2010-4255, CVE-2010-4263, CVE-2010-4343, CVE-2010-4526, CVE-2010-4249, CVE-2010-4251, CVE-2010-4655, CVE-2010-4346, CVE-2011-0521, CVE-2011-0710, CVE-2011-1010, CVE-2011-1090, and CVE-2011-1478 to these issues.
- Updates the glibc third-party library to resolve multiple security issues. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2010-0296, CVE-2011-0536, CVE-2011-1071, CVE-2011-1095, CVE-2011-1658, and CVE-2011-1659 to these issues.
In addition, this patch contains updated pre-built kernel driver modules for Ubuntu 10.04.2 and 10.04.3.
Deployment Considerations
None beyond the required patch bundles and reboot information listed in the table above.
Patch Download and Installation
See the VMware vCenter Update Manager Administration Guide for instructions on using Update Manager to download and install patches to automatically update ESX 4.0 hosts.
To update ESX 4.0 hosts when not using Update Manager, download the patch ZIP file from http://support.vmware.com/selfsupport/download/ and install the bulletin using esxupdate from the command line of the host. For more information, see the ESX 4.0 Patch Management Guide.
Request a Product Feature
- Updated:
- Categories:
- Languages:
- Product Family:
- Product(s):
- Product Version(s):

