Note: This is an archival copy of Security Sun Alert 257329 as previously published on http://sunsolve.sun.com.|
Latest version of this security advisory is available from http://support.oracle.com as Sun Alert 1020386.1.
Sun Fire V215 Server
Date of Resolved Release
A security vulnerability in certain system board firmware revisions of Sun Fire V215 servers with XVR-100 graphic cards may allow an unprivileged user to panic the system:
On Sun Fire V215 servers with XVR-100 graphic cards and certain system board revisions, a security vulnerability in the system board firmware may allow a local or remote unprivileged user to panic the system and thereby cause a Denial of Service (DoS).
2. Contributing Factors
This issue can occur on the following platform:
To determine the installed system board part number and dash level, the Solaris prtfru(1M) command can be used:
$ prtfru -x
To determine if an XVR-100 graphic card is present, the following command can be used:
# prtdiag | grep XVR-100To determine if a -04 board has already received the fix from patch 142186-01, do the following:
From the OBP prompt:
If the described issue occurs, the system may experience a PCIe related panic similar to the following:
panic[cpu1]/thread=30001bd89a0: px#0: Fatal PCIe Fabric Error has occurred...4. Workaround
There is no workaround for this issue. Please see the Resolution section below.
This issue is addressed in the following release:
For more information on Security Sun Alerts, see 1009886.1.
Copyright 2000-2009 Sun Microsystems, Inc., 4150 Network Circle, Santa Clara, CA 95054 U.S.A. All rights reserved.
06-Aug-2009: Updated Contributing Factors section.
14-Aug-2009: Updated Resolution section.
This solution has no attachment