Knowledge Base

The VMware Knowledge Base provides support solutions, error messages and troubleshooting guides
 
Search the VMware Knowledge Base (KB)   View by Article ID
 

VMware ESXi 4.0, Patch ESXi400-201104401-SG: Updates Firmware (1037259)

Details

Release date: April 28, 2011

Patch Classification Security
Build Information See KB 1037261.
Host Reboot Required Yes
Virtual Machine Migration or Shutdown Required Yes
PRs Fixed 702120, 702107
Affected Hardware N/A
Affected Software N/A
Related CVE numbers CVE-2011-1785

 

Solution

Summaries and Symptoms

This patch updates the Certificate Revocation List (CRL) to revoke an RSA key that HP uses for code-signing certain software components. HP server contains a new key pair and has re-signed the affected software components with the new key.
On an HP system, if you apply this patch and then restart the ESXi system, you must update the software components to the version signed with the new key. If you do not restart the system, it continues to work with the currently installed and loaded software. However, the ESXi system rejects software signed with the revoked key and logs a warning if the system loads any kernel module signed with the revoked key. This might cause certain HP features to fail.

This patch also resolves an issue where the ESXi system might lose connection with the vCenter Server intermittently due to socket exhaustion.
By sending malicious network traffic to an ESXi system, an attacker might exhaust the available sockets and prevent further connections to the system. In this scenario, a system becomes inaccessible, its virtual machines continue to run and have network connectivity but a reboot of the ESXi system might be required in order to be able to connect to the machine again.
The ESXi system might intermittently lose connectivity caused by applications that do not correctly close sockets. If this occurs, an error message similar to the following might be written to the vpxa log file:
socket() returns -1 (Cannot allocate memory)
An error message similar to the following might be written to the VMkernel log file:
socreate(type=2, proto=17) failed with error 55
The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2011-1785 to this issue.

Deployment Considerations

None beyond the required patch bundles and reboot information listed in the table above.

Patch Download and Installation

The typical way to apply patches to ESXi systems is through the VMware Update Manager. For details, see the VMware vCenter Update Manager Administration Guide.

ESXi systems can also be updated using vSphere Host Update Utility or by manually downloading the patch ZIP file from the VMware download page and installing the bulletin by using the vihostupdate command through the vSphere CLI. For details, see the vSphere CLI Installation and Reference Guide and the vSphere Upgrade Guide.
 

Request a Product Feature

To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.

Feedback

  • 1 Ratings

Did this article help you?
This article resolved my issue.
This article did not resolve my issue.
This article helped but additional information was required to resolve my issue.
What can we do to improve this information? (4000 or fewer characters)
  • 1 Ratings
Actions
KB: