...
Release date: August 14, 2018 Patch CategoryBugfixPatch SeverityImportantHost Reboot RequiredYesVirtual Machine Migration or Shutdown RequiredYesAffected HardwareN/AAffected SoftwareN/AVIBs Included VMware_bootbank_cpu-microcode_6.0.0-3.100.9313334 PRs FixedN/ARelated CVE numbersN/A
Summaries and Symptoms This patch updates cpu-microcode VIB to resolve the following issue: This ESXi patch provides part of the hypervisor-specific mitigation of CVE-2018-3646. For important details on this mitigation, see VMware Security Advisory VMSA-2018-0020. The table below lists the Intel processors for which microcode updates are included in this patch. Please contact your hardware vendor to determine if BIOS or firmware updates are recommended as there may be additional improvements included with those updates. Microcode updates are necessary for ESXi to provide the speculative-execution control mechanisms for ESXi to mitigate CVE-2018-3646. VMware has included microcode updates in this ESXi patch to simplify deployment processes and minimize downtime. Code Name FMS Plt ID MCU Rev MCU Date Brand Names Nehalem-EP 0x106a5 03 0x0000001d 05/11/2018 Intel Xeon 35xx Series; Intel Xeon 55xx Series Lynnfield 0x106e5 13 0x0000000a 05/08/2018 Intel Xeon 34xx Lynnfield Series Clarkdale 0x20652 12 0x00000011 05/08/2018 Intel i3/i5 Clarkdale Series; Intel Xeon 34xx Clarkdale Series Arrandale 0x20655 92 0x00000007 04/23/2018 Intel Core i7-620LE Processor Sandy Bridge DT 0x206a7 12 0x0000002e 04/10/2018 Intel Xeon E3-1100 Series; Intel Xeon E3-1200 Series; Intel i7-2655-LE Series; Intel i3-2100 Series Westmere EP 0x206c2 03 0x0000001f 05/08/2018 Intel Xeon 56xx Series; Intel Xeon 36xx Series Sandy Bridge EP 0x206d7 6d 0x00000714 05/08/2018 Intel Pentium 1400 Series; Intel Xeon E5-1400 Series; Intel Xeon E5-1600 Series; Intel Xeon E5-2400 Series; Intel Xeon E5-2600 Series; Intel Xeon E5-4600 Series Nehalem EX 0x206e6 04 0x0000000d 05/15/2018 Intel Xeon 65xx Series; Intel Xeon 75xx Series Westmere EX 0x206f2 05 0x0000003b 05/16/2018 Intel Xeon E7-8800 Series; Intel Xeon E7-4800 Series; Intel Xeon E7-2800 Series Ivy Bridge DT 0x306a9 12 0x00000020 04/10/2018 Intel i3-3200 Series; Intel i7-3500-LE/UE, Intel i7-3600-QE, Intel Xeon E3-1200-v2 Series; Intel Xeon E3-1100-C-v2 Series; IntelPentium B925C Haswell DT 0x306c3 32 0x00000025 04/02/2018 Intel Xeon E3-1200-v3 Series Ivy Bridge EP 0x306e4 ed 0x0000042d 04/25/2018 Intel Xeon E5-4600-v2 Series; Intel Xeon E5-2400-v2 Series; Intel Xeon E5-2600-v2 Series; Intel Xeon E5-1400-v2 Series; Intel Xeon E5-2600-v2 Series Ivy Bridge EX 0x306e7 ed 0x00000714 04/25/2018 Intel Xeon E7-8800/4800/2800-v2 Series Haswell EP 0x306f2 6f 0x0000003d 04/20/2018 Intel Xeon E5-2400-v3 Series; Intel Xeon E5-1400-v3 Series; Intel Xeon E5-1600-v3 Series; Intel Xeon E5-2600-v3 Series; Intel Xeon E5-4600-v3 Series Haswell EX 0x306f4 80 0x00000012 04/20/2018 Intel Xeon E7-8800/4800-v3 Series Broadwell H 0x40671 22 0x0000001e 04/03/2018 Intel Core i7-5700EQ; Intel Xeon E3-1200-v4 Series Broadwell EP/EX 0x406f1 ef 0x0b00002e 04/19/2018 Intel Xeon E7-8800/4800-v4 Series; Intel Xeon E5-4600-v4 Series; Intel Xeon E5-2600-v4 Series; Intel Xeon E5-1600-v4 Series Skylake SP 0x50654 b7 0x0200004d 05/15/2018 Intel Xeon Platinum 8100 (Skylake-SP) Series; Intel Xeon Gold 6100/5100, Silver 4100, Bronze 3100 (Skylake-SP) Series Broadwell DE 0x50662 10 0x00000017 05/25/2018 Intel Xeon D-1500 Series Broadwell DE 0x50663 10 0x07000013 04/20/2018 Intel Xeon D-1500 Series Broadwell DE 0x50664 10 0x0f000012 04/20/2018 Intel Xeon D-1500 Series Broadwell NS 0x50665 10 0x0e00000a 04/20/2018 Intel Xeon D-1500 Series Skylake H/S 0x506e3 36 0x000000c6 04/17/2018 Intel Xeon E3-1500-v5 Series; Intel Xeon E3-1200-v5 Series Kaby Lake H/S/X 0x906e9 2a 0x0000008e 03/24/2018 Intel Xeon E3-1200-v6 Patch Download and Installation The typical way to apply patches to ESXi hosts is through the VMware vSphere Update Manager. For details, see the Installing and Administering VMware vSphere Update Manager. ESXi hosts can be updated by manually downloading the patch ZIP file from the VMware download page and installing the VIB by using the esxcli software vib command. Additionally, the system can be updated using the image profile and the esxcli software profile command. For details, see the vSphere Command-Line Interface Concepts and Examples and the vSphere Upgrade Guide.
Click on a version to see all relevant bugs
VMware Integration
Learn more about where this data comes from
Bug Scrub Advisor
Streamline upgrades with automated vendor bug scrubs
BugZero Enterprise
Wish you caught this bug sooner? Get proactive today.