K-3
×
PREV vStack Reference NEXT

This host is potentially vulnerable to issues described in CVE-2018-3646

vmware · 2021-12-11 · 1 min · never revised · entry 19/48

NAME

cve-2018-3646 - clear the L1TF warning on ESXi 6.7 by enabling the side-channel-aware scheduler version 2

DESCRIPTION

We came across the following warning in one of our clusters running ESXi 6.7.0, 17700523 (latest build)

After some searching, performing the following steps from kb article 55806 solved the issue for us.

Enabling the ESXi Side-Channel-Aware Scheduler Version 2 (SCAv2) using ESXi Embedded Host Client

  1. Connect to the ESXi host by opening a web browser to https://HOSTNAME.
  2. Click Manage under host navigator.
  3. Click the Advanced settings Tab.
  4. Use the search box to find VMkernel.Boot.hyperthreadingMitigation.

Here you can see that  VMkernel.Boot.hyperthreadingMitigation is set to ‘false’

  1. Select the VMkernel.Boot.hyperthreadingMitigation setting and click the Edit Option.
  2. Change the configuration option to true (default: false).
  3. Click Save.
  1. Use the search box to find VMkernel.Boot.hyperthreadingMitigationIntraVM.
  2. Select the VMkernel.Boot.hyperthreadingMitigationIntraVM setting and click the Edit Option.
  3. Change the configuration option to false (default: true).
  4. Click Save.
  5. Reboot the ESXi host for the configuration change to go into effect.

As you could see in the ‘Edit Advanced System Settings’ screenshots, VMkernel.Boot.hyperthreadingMitigationIntraVM already had the correct status which is ‘true’.

SEE ALSO

hostprofile-vs-config(8), vmdk-lock(8), vcf-study-guide(8), vmware(7)

vStack 2021-12-11 read 
PSU 1   ONLINE   230V   feed A   2.3 A
PSU 2   ONLINE   230V   feed B   2.0 A
online activity revised, or quiet for a while empty slot
vStack 2026 RSS