Categories: vSphere

XXX esx.problem.hyperthreading.unmitigated.formatonhost not found XXX Warning on ESXi 6.x

I have recently applied the latest patches on vSphere 6.0 version and after applying patches hosts was showing  with warning message

” XXX esx.problem.hyperthreading.unmitigated.formatonhost not found XXX “  . This messages come after applying latest patches available in VMSA-2018-0020 to mitigate CVE-2018-3646 introduced a new notification to indicate the remediation status of the ‘L1 Terminal Fault’ (L1TF – VMM) vulnerability.

Note :- If you perform this you will loose the HT functionality , and suppress the warning is not recommended since your environment will vulnerable  , VMware team is working on a solution to solve this issue . So before proceeding this update , please check your resources , security,requirement.

There are multiple option to resolve this using CLI ,  if you are not experienced with CLI part no worries it is very easy to perform form vSphere or WebClinet , using below steps

  1. Connect to the vCenter Server using either the vSphere Web or vSphere Client.
  2. Select an ESXi host in the inventory.
  3. Click the Manage Tab from vSphere 6.x Host
  4. Click the Settings sub-tab.
  5. Under the System heading, click Advanced System Settings.
  6. Click in the Filter box and search VMkernel.Boot.hyperthreadingMitigation
  7. Select the setting by name and click the Edit pencil icon.
  8. Change the configuration option to true (default: false).
  9. Click OK.
  10. Reboot the ESXi host for the configuration change to go into effect.

Using ESXCLI to Perform this Operation

  1. SSH to an ESXi host or open a console where the remote ESXCLI is installed.
  2. Check the current runtime value of the HTAware Mitigation Setting by running below comand

#esxcli system settings kernel list -o hyperthreadingMitigation

  1. Enable HT Aware Mitigation by running below command
        #esxcli system settings kernel set -s hyperthreadingMitigation -v TRUE
  1. Reboot the ESXi host for the configuration change to go into effect.

This is Applicable for Below vSphere versions

  • VMware vSphere ESXi 5.5
  • VMware vSphere ESXi 6.0
  • VMware vSphere ESXi 6.5
  • VMware ESXi 6.7

Important Notes 

Following list summarizes potential problem areas after enabling the ESXi Side-Channel-Aware Scheduler:

  • VMs configured with vCPUs greater than the physical cores available on the ESXi host
  • VMs configured with custom affinity or NUMA settings
  • VMs with latency-sensitive configuration
  • ESXi hosts with Average CPU Usage greater than 70%
  • Hosts with custom CPU resource management options enabled
  • HA Clusters where a rolling upgrade will increase Average CPU Usage above 100%

And this issue is still currently under investigation by VMware Engineers  and Intel , and to fully utilize hypertrophying you will have to roll back at this moment  .

Not advised to suppress the Warning since suppressing will make your environment vulnerable .

Reference – VMware KB

Reference – VMware KB

Reference – VMware Security Advisory

Reference – VMware KB

Rajesh Radhakrishnan

Recent Posts

NAKIVO Backup & Replication v10.8 Released With New Features

Nakivo has released its new Backup and Replication solution Nakivo v10.8, which includes support for…

2 years ago

Oracle Cloud VMware Solution and Features

Oracle Cloud VMware Solution (OCVS) provides a customer-managed, native VMware-based cloud environment hosted in Oracle…

2 years ago

Vinchin Backup and Recovery Review

Vinchin is a professional provider of data protection solutions for enterprises. It provides a series…

2 years ago

VMware Cloud Disaster Recovery (VCDR) Solution Deployment And Configuration Part 2

In my previous blog post, I have explained about VMware Cloud Disaster Recovery (VCDR) Onboarding and…

2 years ago

How to Deploy vRNI Cloud With VMC on AWS

vRealize Network Insight helps you build an optimized, highly available, and secure network infrastructure across…

2 years ago

This SysAdmin Day, WIN with Hornetsecurity!

Can you believe it's here again? SysAdmin Day is back, and with it comes endless gratitude…

2 years ago