ESXi Patches – November 2020
Today, all news is about Trump and Biden but US president can’t help you about keep safe your virtualization environments. Also you can’t keep safe even by using wooden plate. Go to my.vmware.com and download the new patches.
Security is Always Important But Not Everything
“Security is Always Important But Not Everything”, Ok… but the patches released all about vulnerabilities mitigations.
All supporting versions are affected by the below issue:
OpenSLP as used in ESXi has a use-after-free issue. This issue might allow a malicious actor with network access to port 427 on an ESXi host to trigger a use-after-free in the OpenSLP service resulting in remote code execution. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2020-3992 to this issue. This patch contains the complete fix for CVE-2020-3992. For more information, see VMware Security Advisory VMSA-2020-0023.1.
ESXi Patches Release Notes
ESXi 7.0
Imageprofile ESXi-7.0U1a-17119627-standard (Build 17119627) includes the following updated VIBs:
Name | Version | Vendor | Summary | Category | Severity | Bulletin |
---|---|---|---|---|---|---|
cpu-microcode | 7.0.1-0.10.17119627 | VMware | CPU microcode updates | security | important | ESXi_7.0.1-0.10.17119627 |
crx | 7.0.1-0.10.17119627 | VMware | CRX related bits | security | important | ESXi_7.0.1-0.10.17119627 |
esx-base | 7.0.1-0.10.17119627 | VMware | ESXi base system | security | important | ESXi_7.0.1-0.10.17119627 |
esx-dvfilter-generic-fastpath | 7.0.1-0.10.17119627 | VMware | dvfilter-generic-fastpath module | security | important | ESXi_7.0.1-0.10.17119627 |
esx-update | 7.0.1-0.10.17119627 | VMware | ESXi install/upgrade components. | security | important | esx-update_7.0.1-0.10.17119627 |
esx-xserver | 7.0.1-0.10.17119627 | VMware | ESXi X.Org Xserver | security | important | ESXi_7.0.1-0.10.17119627 |
gc | 7.0.1-0.10.17119627 | VMware | SystemStorage extra for ESX 7.0 | security | important | ESXi_7.0.1-0.10.17119627 |
loadesx | 7.0.1-0.10.17119627 | VMware | Provides QuickBoot functionality. | security | important | esx-update_7.0.1-0.10.17119627 |
native-misc-drivers | 7.0.1-0.10.17119627 | VMware | VMware Esx VIB | security | important | ESXi_7.0.1-0.10.17119627 |
vdfs | 7.0.1-0.10.17119627 | VMware | ESXi VDFS | security | important | ESXi_7.0.1-0.10.17119627 |
vsan | 7.0.1-0.10.17119627 | VMware | VSAN ESXi | security | important | ESXi_7.0.1-0.10.17119627 |
vsanhealth | 7.0.1-0.10.17119627 | VMware | ESXi VSAN Health Service | security | important | ESXi_7.0.1-0.10.17119627 |
(For more information see Release Notes.)
ESXi 6.7
Imageprofile ESXi-6.7.0-20201103001-standard (Build 17098360) includes the following updated VIBs:
Name | Version | Vendor | Summary | Category | Severity | Bulletin |
---|---|---|---|---|---|---|
esx-base | 6.7.0-3.123.17098360 | VMware | ESXi base system | security | important | ESXi670-202011301-SG |
esx-update | 6.7.0-3.123.17098360 | VMware | ESXi install/upgrade components. | security | important | ESXi670-202011301-SG |
vsan | 6.7.0-3.123.17067304 | VMware | VSAN ESXi | security | important | ESXi670-202011301-SG |
vsanhealth | 6.7.0-3.123.17067305 | VMware | ESXi VSAN Health Service | security | important | ESXi670-202011301-SG |
(For more information see Release Notes.)
ESXi 6.5
Imageprofile ESXi-6.5.0-20201104001-standard (Build 17097218) includes the following updated VIBs:
Name | Version | Vendor | Summary | Category | Severity | Bulletin |
---|---|---|---|---|---|---|
esx-base | 6.5.0-3.146.17097218 | VMware | Updates the ESX 6.5.0 esx-base | security | critical | ESXi650-202011401-SG |
esx-tboot | 6.5.0-3.146.17097218 | VMware | Updates the ESX 6.5.0 esx-tboot | security | critical | ESXi650-202011401-SG |
vsan | 6.5.0-3.146.17067204 | VMware | Updates the ESX 6.5.0 vsan | bugfix | critical | ESXi650-202011401-SG |
vsanhealth | 6.5.0-3.146.17067206 | VMware | ESXi VSAN Health Service | security | important | ESXi650-202011401-SG |
(For more information see Release Notes.)
Workaround
Find the workaround on this VMware KB: https://kb.vmware.com/s/article/76372
See Also
Network Connection Problem on HPE FlexFabric 650 (FLB/M) Adapter