"Warning: VMKernel Live Patch can still proceed, but not all kernel processes could be scanned for completion of unpatched code execution"
search cancel

"Warning: VMKernel Live Patch can still proceed, but not all kernel processes could be scanned for completion of unpatched code execution"

book

Article ID: 434517

calendar_today

Updated On:

Products

VMware vCenter Server VMware vSphere ESXi

Issue/Introduction

  • When performing a Live Patch that contains fixes for the VMkernel, the lifecycle manager (vLCM) runs prechecks on each patched ESX host. For some patches, require the ability to detect unpatched code execution after the patch activation. During the prechecks, the host self-tests this ability. If an error occurs during the self-test, a warning message displays: “VMKernel Live Patch can still proceed, but not all kernel processes could be scanned for completion of unpatched code execution. This may result in compliance issues after remediation”. This indicates that the patched host might not be in a compliant state after the remediation because the system cannot verify that unpatched code isn’t running anymore.

    NOTE: This does not prevent the patch from being applied.

Environment

  • vCenter 9.1.x
  • ESX 9.1.x

Resolution

If the host is not compliant after the remediation because of this, a host reboot is required to make the host compliant.

Additional Information

As indicated above, this does not prevent a given patch from being applied. It doesn’t mean either that the patch is not working as expected. It means that the system cannot strictly prove that unpatched code is not running anymore.