VMware Cloud Community
biggizod
Contributor
Contributor

Spectre/Meltdown: CVE-2017-5753 / CVE-2017-5754 / CVE-2017-5715

Hi guys. We have UCS servers c220 with ESXI6.0.0 on it.

1 Do I need to apply patch ESXi600-201711001  first then ESXi600-201803001 Or ESXi600-201803001 is enough (KB52085)?

2 Those esxi are not connected to Vcenter so I have to patch manually , can you please share steps to do it or link?

Thank you

Tags (3)
0 Kudos
2 Replies
Tibmeister
Expert
Expert

The esxbase patches are cumulative, so you only need to apply the latest.  The reason is that ESXi is firmware, so unlike Linux or Windows patching you don't replace only certain libraries, instead in ESXi you replace the entire firmware image by replacing the boot bank.  So short answer, no, just apply ESXi600-201803001 and you are good, but remember you must able vCenter 6 U3e BEFORE installing this patch if you use EVC mode. 

Even then, you are not 100% done because all VM's need to be hardware version 9 or above (11 recommended) and the tools need to be updated, even if the are the OSP version of the tools.  But the tools upgrade is after the ESXi patch, so the order is VC -> ESXi -> VM HW -> VM Tools.  And even then, you are not 100% because all the vCenter 6 U3e patch does is enable the new EVC functionality to patch the vulnerability in the guest, there will be a vCenter 6 U3f that will be coming that is the patch for Spectre inside of the vCenter appliance itself.  Only then are you complete for the remediation, and remember that only Spectre is applicable to ESXi and vCenter, Meltdown is only applicable to the guest OS installs.

0 Kudos
biggizod
Contributor
Contributor

thank you for respond. As I mentioned my ESXi  hosts are not in vcenter, and not connected to internet,  they were deployed by cisco for cisco collaboration. So I am looking for instructions to patch them manually cause I can't use vcenter and other tools I could use if we buy license.

Anyone can share steps or link to patch it manually or via cli ? 

0 Kudos