VMware

VMware ESX Server 2.5.5 Upgrade Patch 15 (for 2.5.5 Systems Only)

Released 10/27/09

TAR File

This document contains the following information:

Security Issues

This release addresses a security vulnerability in exception handling. Improper setting of the exception code on page faults might allow for local privilege escalation on the guest.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2009-2267 to this issue.
Refer VMware Security Center for regular updates to the VMware Security Advisories.

Applicability

This patch is an ESX Server 2.5.5 patch. Ensure that ESX Server 2.5.5 build 57619 or later is installed before applying the patch. Run vmware -v to see the version and build information for your ESX Server installation.

Installing the Update

Note: Back up your ESX Server installation before installing this patch. Also, a minimum of 350MB of temporary free space on the / file system is required for installing this patch.

This update requires you to boot your server into Linux mode to perform the upgrade. When you are prompted to reboot at the end of the upgrade, the installer restarts your system to run ESX Server.

  1. Power off all virtual machines.
  2. Restart your system.
  3. At the LILO Boot Menu, select the option appropriate for your system.
    • For a boot-from-SAN installation, select esx-san-safe.
    • For all other installations, select linux-up.
  4. Log in as root to the ESX Server service console.
  5. Download the tar file into a temporary directory under /root on your ESX Server service console.
  6. Change your working directory to that directory.
  7. Verify the integrity of the package:
    # md5sum esx-2.5.5-191611-upgrade.tar.gz

    The md5 checksum output should match the following:
    c346fe510b6e51145570e03083f77357 esx-2.5.5-191611-upgrade.tar.gz

  8. Extract the compressed tar archive:
    # tar -xvzf esx-2.5.5-191611-upgrade.tar.gz
  9. Change to the newly created directory:
    # cd esx-2.5.5-191611-upgrade
  10. Run the installer:
    # ./upgrade.pl
    The system updates have now been installed. A reboot prompt is displayed:
    Reboot the server now [y/n]?

    This update will not be complete until you reboot the ESX Server host. If you enter n to indicate that you will not reboot the server at this time, ESX Server displays the warning message: Please reboot the server manually. Your virtual machines will not run properly until this is done. If you see this message, you must manually reboot the server to complete the upgrade.

  11. At the reboot prompt, enter y to reboot the server.