10-06-2025 05:00 AM
Hi Team,
I could see 3 SMU patches for the 17.15.3 version for 9800-L-F WLC.
Can anyone let me know which SMU patch to be installed. Or I have to install all the 3 SMUs? Is it mandatory to install SMU?
Solved! Go to Solution.
10-06-2025 06:13 AM
As @Mark Elsen mentioned, every SMU serves a different purpose, provides fix to specific defects. Now the PSIRT bundle is for vulnerability fixes - which is applicable for most of the customers. If you are managing the WLC via CatC and doing provisioning then you can apply the 3rd one. But if you are not doing or having CatC, no need for this SMU. The 2nd one is for memory leak - which is not a catastrophic defect by nature - which means you can bypass this for the time being. There are other SMUs as well which are for specific use cases and available only through request. So long story short - first one you can apply. 3rd one you can apply if you have CatC and doing provisioning. 2nd one can be ignored for the time being.
10-06-2025 05:16 AM
- @Bdas1 Whether it's mandatory depends if you are experiencing the mentioned problem in the SMU
description or not (and want to fix it deciding yes or no)>
Each SMU is independent and must be installed individually for it's purpose
M.
10-06-2025 05:24 AM
Thank you Mark for your response. The WLC is running on older version and I want to move to a suggested release. So far the bugs mentioned have not impacted. However, since going to a new version, I want to make sure I have all the patches also installed. So, wanted to make sure if it is better to install all the 3 SMUs?
10-06-2025 06:13 AM
As @Mark Elsen mentioned, every SMU serves a different purpose, provides fix to specific defects. Now the PSIRT bundle is for vulnerability fixes - which is applicable for most of the customers. If you are managing the WLC via CatC and doing provisioning then you can apply the 3rd one. But if you are not doing or having CatC, no need for this SMU. The 2nd one is for memory leak - which is not a catastrophic defect by nature - which means you can bypass this for the time being. There are other SMUs as well which are for specific use cases and available only through request. So long story short - first one you can apply. 3rd one you can apply if you have CatC and doing provisioning. 2nd one can be ignored for the time being.
10-06-2025 02:18 PM
Do not install SMU nor APSP just for "sh*ts-n-giggles". Install the SMU &/or APSP only when certain bugs have been encountered.
There are several bugs/crashes which are caused by installing SMU or APSP.
10-06-2025 04:37 PM
I would consider the security PSIRT SMU essential.
The other 2 address these bugs:
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwq73135
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwo95396
All 3 of them are hitless - meaning WLC reload is not required.
You can see the TAC recommendations at https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214749-tac-recommended-ios-xe-builds-for-wirele.html#toc-hId--2128232276
10-06-2025 06:14 PM
@Rich R wrote:
I would consider the security PSIRT SMU essential.
I agree and I completely forgot about to mention this.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide