Quantcast
Channel: VMware Communities: Message List
Viewing all articles
Browse latest Browse all 229915

Re: Spectre/Meltdown: CVE-2017-5753 / CVE-2017-5754 / CVE-2017-5715

$
0
0

The esxbase patches are cumulative, so you only need to apply the latest.  The reason is that ESXi is firmware, so unlike Linux or Windows patching you don't replace only certain libraries, instead in ESXi you replace the entire firmware image by replacing the boot bank.  So short answer, no, just apply ESXi600-201803001 and you are good, but remember you must able vCenter 6 U3e BEFORE installing this patch if you use EVC mode. 

Even then, you are not 100% done because all VM's need to be hardware version 9 or above (11 recommended) and the tools need to be updated, even if the are the OSP version of the tools.  But the tools upgrade is after the ESXi patch, so the order is VC -> ESXi -> VM HW -> VM Tools.  And even then, you are not 100% because all the vCenter 6 U3e patch does is enable the new EVC functionality to patch the vulnerability in the guest, there will be a vCenter 6 U3f that will be coming that is the patch for Spectre inside of the vCenter appliance itself.  Only then are you complete for the remediation, and remember that only Spectre is applicable to ESXi and vCenter, Meltdown is only applicable to the guest OS installs.


Viewing all articles
Browse latest Browse all 229915

Trending Articles