Multiple hostdCgiServer core dumps being created on ESXi hosts
search cancel

Multiple hostdCgiServer core dumps being created on ESXi hosts

book

Article ID: 317894

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

Symptoms:

You may observe the following issues:

1.  Connections to the host(s) drop unexpectedly.

2.  Multiple hostdCgiServer-zdump files created in /var/core

3.  In a DRS cluster, DRS may move all VM's to a single host, or fewer hosts due to the service crashes making these hosts unavailable for DRS.

4.  You see the following or similar in the vobd.log file:

[UserWorldCorrelator] 646511084069us: [esx.problem.hostd.core.dumped] /bin/hostdCgiServer crashed (3 time(s) so far) and a core file may have been created at /var/core/hostdCgiServer-zdump.002. This may have caused connections to the host to be dropped.

5.  The customer is utilizing a Qualys scanning tool in their environment, or possibly another similar tool/script.


Environment

VMware vSphere 7.0.x

Cause

The crash is caused by a malformed header URL sent to the cgi server:
 
//cgi-bin/ShellExample.cgi?/Library/*

The duplicate "/" is not valid and should not reach the server, and if it does it causes a crash.

Resolution

This issue is resolved in vSphere ESXi 7.0 U3i (build number 20842708).

Workaround:
Stop the scanning tool or other script from using the malformed header.