{"id":34538,"date":"2018-08-20T09:00:34","date_gmt":"2018-08-20T07:00:34","guid":{"rendered":"https:\/\/nolabnoparty.com\/?p=34538"},"modified":"2023-07-16T11:30:31","modified_gmt":"2023-07-16T09:30:31","slug":"l1-terminal-fault-l1tf-vulnerability-vsphere-patches-available","status":"publish","type":"post","link":"https:\/\/nolabnoparty.com\/en\/l1-terminal-fault-l1tf-vulnerability-vsphere-patches-available\/","title":{"rendered":"L1 Terminal Fault (L1TF) vulnerability: vSphere patches available"},"content":{"rendered":"<p><img decoding=\"async\" class=\"aligncenter wp-image-34555 size-full\" title=\"l1tf-vsphere- patches-01\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2018\/08\/l1tf-vsphere-patches-01.jpg\" alt=\"l1tf-vsphere- patches-01\" width=\"602\" height=\"202\" \/><\/p>\n<p>After the vulnerabilities <a href=\"https:\/\/nolabnoparty.com\/en\/vmware-new-security-patch-vcenter-server-6-5-u1f\/\">Spectre and Meltdown<\/a>, a\u00a0recently identified speculative execution side-channel method called <a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/architecture-and-technology\/l1tf.html\" target=\"_blank\" rel=\"noopener\">L1 Terminal Fault<\/a> (L1TF) has been shared from Intel.<\/p>\n<p>Similar to\u00a0Spectre and Meltdown issues, L1TF vulnerability\u00a0<strong>affects only Intel Core and Xeon processors<\/strong>\u00a0where a malicious code running in these CPUs could read data it is not entitled to from another process.<!--more--><\/p>\n<p>VMware already <strong>released some patches<\/strong>\u00a0to fix this problem as reported in the VMware Security Advisories <a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0020.html?src=af_5acfd7716582e&amp;cid=70134000001YR6X\" target=\"_blank\" rel=\"noopener\">VMSA-2018-0020<\/a>. Since the process to identify affected hosts may take some time, solutions like <a href=\"https:\/\/nolabnoparty.com\/en\/runecast-analyzer-1-6-5-detects-meltdown-spectre-chip-issues\/\">Runecast Analyzer<\/a> can help to identify critical hosts in <strong>matter of seconds<\/strong>.<\/p>\n<p>&nbsp;<\/p>\n<h2>VMware L1TF patches<\/h2>\n<p>On\u00a0 August, 14th 2018 VMware released some patches for vCenter Server and ESXi to mitigate L1TF vulnerability.<\/p>\n<p>&nbsp;<\/p>\n<h4>vCenter Server<\/h4>\n<p>VMware released vCenter Server patches for the following releases:<\/p>\n<ul>\n<li><strong>vCenter Server 6.7<\/strong> - <a href=\"https:\/\/docs.vmware.com\/en\/VMware-vSphere\/6.7\/rn\/vsphere-vcenter-server-670d-release-notes.html\" target=\"_blank\" rel=\"noopener\">VC 6.7.0d build 9451876<\/a><\/li>\n<li><strong><strong>vCenter Server\u00a0<\/strong>6.5<\/strong> - <a href=\"https:\/\/docs.vmware.com\/en\/VMware-vSphere\/6.5\/rn\/vsphere-vcenter-server-65u2c-release-notes.html\" target=\"_blank\" rel=\"noopener\">VC 6.5 Update 2c - build 9451637<\/a><\/li>\n<li><strong><strong><strong>vCenter Server\u00a0<\/strong><\/strong>6.0<\/strong> - <a href=\"https:\/\/docs.vmware.com\/en\/VMware-vSphere\/6.0\/rn\/vsphere-vcenter-server-60u3h-release-notes.html\" target=\"_blank\" rel=\"noopener\">VC 6.0 Update 3h - build 9451619<\/a><\/li>\n<li><strong><strong><strong><strong>vCenter Server\u00a0<\/strong><\/strong><\/strong>5.5<\/strong> - <a href=\"https:\/\/docs.vmware.com\/en\/VMware-vSphere\/5.5\/rn\/vsphere-vcenter-server-55u3j-release-notes.html\" target=\"_blank\" rel=\"noopener\">VC 5.5 Update 3j - build 9313450<\/a><\/li>\n<\/ul>\n<p>To patch the vCenter Server proceed <strong>as you normally do<\/strong> when new updates are released.<\/p>\n<p>If the vCSA is used in your infrastructure, patches can be <strong>applied using the VAMI<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-34557 size-large\" title=\"l1tf-vsphere- patches-02\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2018\/08\/l1tf-vsphere-patches-02-600x344.jpg\" alt=\"l1tf-vsphere- patches-02\" width=\"600\" height=\"344\" \/><\/p>\n<p>If you run the vCenter Server Windows-based version, <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4343899\/windows-7-update-kb4343899\" target=\"_blank\" rel=\"noopener\">Microsoft patches<\/a> must be applied also to the guest OS because the L1TF creates <strong>vulnerabilities at the OS level<\/strong>.<\/p>\n<p>&nbsp;<\/p>\n<h4>ESXi<\/h4>\n<p>Once the vCenter Server has been patched, you need to patch the ESXi hosts installed in your infrastructure.<\/p>\n<p>VMware released ESXi patches for the following releases:<\/p>\n<ul>\n<li><strong>ESXi 6.7<\/strong> - <a href=\"https:\/\/kb.vmware.com\/s\/article\/56537\" target=\"_blank\" rel=\"noopener\">ESXi670-201808401-BG<\/a><\/li>\n<li><strong>ESXi 6.5<\/strong> - <a href=\"https:\/\/kb.vmware.com\/s\/article\/56547\" target=\"_blank\" rel=\"noopener\">ESXi650-201808401-BG<\/a><\/li>\n<li><strong>ESXi 6.0<\/strong> - <a href=\"https:\/\/kb.vmware.com\/s\/article\/56552\" target=\"_blank\" rel=\"noopener\">ESXi600-201808401-BG<\/a><\/li>\n<li><strong>ESXi 5.5<\/strong> - <a href=\"https:\/\/kb.vmware.com\/s\/article\/56557\" target=\"_blank\" rel=\"noopener\">ESXi550-201808401-BG<\/a><\/li>\n<\/ul>\n<p>Patches for ESXi already include the <strong>code to patch the affected CPUs<\/strong> without installing BIOS or firmware updates released from the hardware vendor.<\/p>\n<p>ESXi hosts can be easily updated using <strong>VUM<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-34559 size-large\" title=\"l1tf-vsphere- patches-03\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2018\/08\/l1tf-vsphere-patches-03-600x350.jpg\" alt=\"l1tf-vsphere- patches-03\" width=\"600\" height=\"350\" \/><\/p>\n<p>&nbsp;<\/p>\n<h2>Mitigate the L1TF issue<\/h2>\n<p>In the\u00a0<a href=\"https:\/\/kb.vmware.com\/s\/article\/55806\" target=\"_blank\" rel=\"noopener\" data-aura-rendered-by=\"11:92;a\">KB55806<\/a>, VMware reports the procedure to mitigate the <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-3646\" target=\"_blank\" rel=\"noopener\">CVE-2018-3646<\/a> vulnerability that includes a three phases process:<\/p>\n<ol>\n<li><strong>Update Phase<\/strong>: apply vSphere updates and patches. vCenter Server must be patched first to avoid problems then the ESXi hosts.<\/li>\n<li><strong>Planning Phase<\/strong>: assess the environment to understand if sufficient CPU capacity is available to avoid operational impacts enabling the <em>ESXi Side-Channel-Aware Scheduler<\/em> needed to mitigate the <em>Concurrent-context attack vector<\/em>.<\/li>\n<li><strong>Scheduler-Enablement Phase<\/strong>: enable the ESXi Side-Channel-Aware Scheduler.<\/li>\n<\/ol>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-34561 size-large\" title=\"l1tf-vsphere- patches-04\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2018\/08\/l1tf-vsphere-patches-04-600x300.jpg\" alt=\"l1tf-vsphere- patches-04\" width=\"600\" height=\"300\" \/><\/p>\n<p>&nbsp;<\/p>\n<h4>Enabling the\u00a0ESXi Side-Channel-Aware Scheduler<\/h4>\n<p>After applying the above patches to ESXi hosts installed in your network, you need to enable the ESXi Side-Channel-Aware Scheduler to <strong>complete the fix process<\/strong>.<\/p>\n<p>From the vSphere Web Client (you can also use the vSphere Client or the ESXi Embedded Host Client) select the ESXi host to process and click the\u00a0<strong>Configure<\/strong> tab.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-34564 size-large\" title=\"l1tf-vsphere- patches-05\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2018\/08\/l1tf-vsphere-patches-05-600x381.jpg\" alt=\"l1tf-vsphere- patches-05\" width=\"600\" height=\"381\" \/><\/p>\n<p>Select <strong>Advanced System Settings<\/strong> under <strong>System<\/strong>\u00a0item and click the <strong>Edit<\/strong> button.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-34566 size-large\" title=\"l1tf-vsphere- patches-06\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2018\/08\/l1tf-vsphere-patches-06-600x298.jpg\" alt=\"l1tf-vsphere- patches-06\" width=\"600\" height=\"298\" \/><\/p>\n<p>Search for <em>VMkernel.Boot.hyperthreadingMitigation<\/em>\u00a0in the <strong>Filter<\/strong> box.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-34568 size-large\" title=\"l1tf-vsphere- patches-07\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2018\/08\/l1tf-vsphere-patches-07-600x442.jpg\" alt=\"l1tf-vsphere- patches-07\" width=\"600\" height=\"442\" \/><\/p>\n<p>By default this parameter is disabled. Set the configuration option to <strong>Enabled<\/strong> and click <strong>OK<\/strong> to confirm.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-34570 size-large\" title=\"l1tf-vsphere- patches-08\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2018\/08\/l1tf-vsphere-patches-08-600x442.jpg\" alt=\"l1tf-vsphere- patches-08\" width=\"600\" height=\"442\" \/><\/p>\n<p>Reboot the ESXi host to apply changes.<\/p>\n<p>&nbsp;<\/p>\n<h2>ESXi Side-Channel-Aware Scheduler impact<\/h2>\n<p>Enabling the ESXi Side-Channel-Aware Scheduler, you may experience some <strong>performance issues<\/strong>\u00a0with a service degradation. Before enabling this parameter read carefully the\u00a0<a href=\"https:\/\/kb.vmware.com\/s\/article\/55767\" target=\"_blank\" rel=\"noopener\">KB55767<\/a>.<\/p>\n<p>Due to these limitations, the ESXi Side-Channel-Aware Scheduler is disabled by default and it's up to the administrators\/organizations to enable this parameter. Leaving the scheduler disabled exposes the host to the\u00a0risk posed by the <strong>Concurrent-context attack vector<\/strong>.<\/p>\n<p><img decoding=\"async\" title=\"signature\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/images\/firma.jpg\" alt=\"signature\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>After the vulnerabilities Spectre and Meltdown, a\u00a0recently identified speculative execution side-channel method called L1 Terminal Fault (L1TF) has been shared from Intel. Similar to\u00a0Spectre and Meltdown issues, L1TF vulnerability\u00a0affects only Intel Core and Xeon processors\u00a0where a malicious code running in these CPUs could read data it is not entitled to from another process.<\/p>\n","protected":false},"author":3,"featured_media":34555,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rop_custom_images_group":[],"rop_custom_messages_group":[],"rop_publish_now":"initial","rop_publish_now_accounts":{"facebook_2879994398731222_17841400390232720":"","mastodon_115463926174894442_115463926174894442":"","linkedin_93tdZWzMZc_93tdZWzMZc":"","bluesky_did:plc:tkabz5kl2rukzdwtuongv3kz_did:plc:tkabz5kl2rukzdwtuongv3kz":""},"rop_publish_now_history":[],"rop_publish_now_status":"pending","footnotes":""},"categories":[903,2701],"tags":[1892,1893,700],"class_list":["post-34538","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-vmware-en","category-vsphere-en","tag-l1tf","tag-patches","tag-vsphere-en","has_thumb"],"_links":{"self":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/posts\/34538","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/comments?post=34538"}],"version-history":[{"count":0,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/posts\/34538\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/media\/34555"}],"wp:attachment":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/media?parent=34538"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/categories?post=34538"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/tags?post=34538"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}