| Summary: | Update request: kernel-3.10.58-1.mga3 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Thomas Backlund <tmb> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | ottoleipala1, rverschelde, sysadmin-bugs, wilcal.int |
| Version: | 3 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA3-32-OK MGA3-64-OK advisory | ||
| Source RPM: | kernel-3.10.58-1.mga3.src.rpm | CVE: | |
| Status comment: | |||
| Bug Depends on: | |||
| Bug Blocks: | 14303 | ||
|
Description
Thomas Backlund
2014-10-16 15:00:04 CEST
Thomas Backlund
2014-10-16 15:01:08 CEST
Blocks:
(none) =>
14303 kernel-server i586 running fine on my Dell Optiplex 990 at work. In VirtualBox, M4, KDE, 32-bit Package(s) under test: kernel-desktop-latest vboxadditions-kernel-desktop-latest default install of kernel-desktop-latest vboxadditions-kernel-desktop-latest [root@localhost wilcal]# uname -a Linux localhost 3.10.54-desktop-2.mga3 #1 SMP Sat Sep 13 14:46:46 UTC 2014 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-3.10.54-2.mga3.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-4.3.16-1.mga3.i586 is already installed System boots to a working desktop. Common apps work. install kernel-desktop-latest & vboxadditions-kernel-desktop-latest from updates_testing [root@localhost wilcal]# uname -a Linux localhost 3.10.58-desktop-1.mga3 #1 SMP Thu Oct 16 08:48:51 UTC 2014 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-3.10.58-1.mga3.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-4.3.18-2.mga3.i586 is already installed System boots to a working desktop. Common apps work. Test platform: Intel Core i7-2600K Sandy Bridge 3.4GHz GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB RTL8111/8168B PCI Express 1Gbit Ethernet DRAM 16GB (4 x 4GB) Mageia 4 64-bit, Nvidia driver virtualbox-4.3.10-1.1.mga4.x86_64 virtualbox-guest-additions-4.3.10-1.1.mga4.x86_64 CC:
(none) =>
wilcal.int (In reply to William Kenney from comment #2) Correction: > In VirtualBox, M4, KDE, 32-bit to In VirtualBox, M3, KDE, 32-bit In VirtualBox, M3, KDE, 64-bit Package(s) under test: kernel-desktop-latest vboxadditions-kernel-desktop-latest default install of kernel-desktop-latest vboxadditions-kernel-desktop-latest [root@localhost wilcal]# uname -a Linux localhost 3.10.54-desktop-2.mga3 #1 SMP Sat Sep 13 14:20:45 UTC 2014 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-3.10.54-2.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-4.3.16-1.mga3.x86_64 is already installed System boots to a working desktop. Common apps work. install kernel-desktop-latest & vboxadditions-kernel-desktop-latest from updates_testing [root@localhost wilcal]# uname -a Linux localhost 3.10.58-desktop-1.mga3 #1 SMP Thu Oct 16 08:23:07 UTC 2014 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-3.10.58-1.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-4.3.18-2.mga3.x86_64 is already installed System boots to a working desktop. Common apps work. Test platform: Intel Core i7-2600K Sandy Bridge 3.4GHz GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB RTL8111/8168B PCI Express 1Gbit Ethernet DRAM 16GB (4 x 4GB) Mageia 4 64-bit, Nvidia driver virtualbox-4.3.10-1.1.mga4.x86_64 virtualbox-guest-additions-4.3.10-1.1.mga4.x86_64 On real hardware, M3, KDE, 32-bit
Package(s) under test:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
default install of:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
[root@localhost wilcal]# uname -a
Linux localhost 3.10.54-desktop-2.mga3 #1 SMP Sat Sep 13 14:46:46 UTC 2014 i686 i686 i686 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-3.10.54-2.mga3.i586 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-4.3.16-1.mga3.i586 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-4.3.16-1.mga3.i586 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-4.3.16-1.mga3.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-4.3.16-1.mga3.i586 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-4.3.16-1.mga3.i586 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-4.3.16-1.mga3.i586 is already installed
[root@localhost wilcal]# lspci -k
00:02.0 VGA compatible controller: Intel Corporation 82915G/GV/910GL Integrated Graphics Controller (rev 04)
Subsystem: Gigabyte Technology Co., Ltd GA-8I915ME-G Mainboard
Kernel driver in use: i915
Kernel modules: i915, intelfb
System boots to a working desktop. Common apps work. M4.1 KDE Live-CD runs as a Vbox client ( very slowly ).
Screen sizes are correct.
install:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
from updates_testing
[root@localhost wilcal]# uname -a
Linux localhost 3.10.58-desktop-1.mga3 #1 SMP Thu Oct 16 08:48:51 UTC 2014 i686 i686 i686 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-3.10.58-1.mga3.i586 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-4.3.18-1.mga3.i586 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-4.3.18-2.mga3.i586 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-4.3.18-1.mga3.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-4.3.18-1.mga3.i586 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-4.3.18-2.mga3.i586 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-4.3.18-1.mga3.i586 is already installed
[wilcal@localhost ~]$ lspci -k
00:02.0 VGA compatible controller: Intel Corporation 82915G/GV/910GL Integrated Graphics Controller (rev 04)
Subsystem: Gigabyte Technology Co., Ltd GA-8I915ME-G Mainboard
Kernel driver in use: i915
Kernel modules: i915, intelfb
System boots to a working desktop. Common apps work. M4.1 KDE Live-CD runs as a Vbox client ( very slowly ).
Screen sizes are correct.
Test platform:
Intel, P4 530J 3.0 GHz, 800MHz FSB, 1MB L2, LGA 775
GigaByte GA-81915G Pro F4 i915G LGA 775 MoBo
Marvel Yukon 88E8001 Gigabit LAN
Intel High Def Audio, Azalia (C-Media 9880) (snd-hda-intel)
Intel Graphics Media Accelerator 900 (Intel 82915G)
Kingston 4GB (2 x 2GB) DDR400 PC-3200
250GB Seagate
Kingwin KF-91-BK SATA Mobile Rack
Kingwin KF-91-T-BK SATA Mobile Rack Tray
Sony CD/DVD-RW DWQ120AB2
On real hardware, M3, KDE, 64-bit
Package(s) under test:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
nvidia-current-kernel-desktop-latest
default install of:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
nvidia-current-kernel-desktop-latest
[root@localhost wilcal]# uname -a
Linux localhost 3.10.54-desktop-2.mga3 #1 SMP Sat Sep 13 14:20:45 UTC 2014 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-3.10.54-2.mga3.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-4.3.16-1.mga3.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-4.3.16-1.mga3.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-4.3.16-1.mga3.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-4.3.16-1.mga3.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-4.3.16-1.mga3.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-4.3.16-1.mga3.x86_64 is already installed
[root@localhost wilcal]# urpmi nvidia-current-kernel-desktop-latest
Package nvidia-current-kernel-desktop-latest-319.60-22.mga3.nonfree.x86_64 is already installed
[root@localhost wilcal]# lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
Subsystem: Gigabyte Technology Co., Ltd Device 3518
Kernel driver in use: nvidia
Kernel modules: nvidiafb, nouveau, nvidia_current
System boots to a working desktop. Common apps work. M4.1 KDE Live-CD runs as a Vbox client ( very slowly ).
Screen sizes are correct.
install:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
nvidia-current-kernel-desktop-latest
from updates_testing
[root@localhost wilcal]# uname -a
Linux localhost 3.10.58-desktop-1.mga3 #1 SMP Thu Oct 16 08:23:07 UTC 2014 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-3.10.58-1.mga3.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-4.3.18-1.mga3.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-4.3.18-2.mga3.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-4.3.18-1.mga3.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-4.3.18-1.mga3.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-4.3.18-2.mga3.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-4.3.18-1.mga3.x86_64 is already installed
[root@localhost wilcal]# urpmi nvidia-current-kernel-desktop-latest
Package nvidia-current-kernel-desktop-latest-319.60-24.mga3.nonfree.x86_64 is already installed
[wilcal@localhost ~]$ lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
Subsystem: Gigabyte Technology Co., Ltd Device 3518
Kernel driver in use: nvidia
Kernel modules: nvidiafb, nouveau, nvidia_current
System boots to a working desktop. Common apps work. M4.1 KDE Live-CD runs as a Vbox client ( very slowly ).
Screen sizes are correct.
Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)
Mageia 4 64-bit, Nvidia driver
virtualbox-4.3.10-1.1.mga4.x86_64
virtualbox-guest-additions-4.3.10-1.1.mga4.x86_64
That's not william real hardware testing it's still inside virtualbox,please real hardware testing means it's installed to hard drive not in virtualbox disk best how to do it is usb hard drive. CC:
(none) =>
ozkyster Otto, please... Wilcal knows what he's doing... He tests both vbox installs and real hw, so he covers both... Advisory: This kernel update is based on upstream -longterm 3.10.58 and fixes the following security issues: The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages (CVE-2014-3601). The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16.3 does not properly implement garbage collection, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via multiple "keyctl newring" operations followed by a "keyctl timeout" operation (CVE-2014-3631). The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both arguments to the pivot_root system call (CVE-2014-7970). The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call (CVE-2014-7975). For other fixes included in this update, read the referenced changelogs. References: https://bugs.mageia.org/show_bug.cgi?id=14302 https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.55 https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.56 https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.57 https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.58 I'm not sure if this will be rebuilt again (synthesis issue requiring new perl-URPM), but this can be validated. I'll leave this to Thomas. Whiteboard:
(none) =>
MGA3-32-OK MGA3-64-OK I don't think the 3.10 branch is affected by the synthesis issue, the issue appeared with the 3.14 branch. We can probably check this by trying to update a pristine Mageia 3 release with updates_testing repos enabled. Or maybe downgrading perl-URPM to the core/release version would be enough. CC:
(none) =>
remi Advisory uploaded. Whiteboard:
MGA3-32-OK MGA3-64-OK =>
MGA3-32-OK MGA3-64-OK advisory I confirm that after reverting to perl-URPM-4.27-1.mga3 from Core Release, I was still able to install the kernel update from testing. Since Thomas is on the move, I guess we have to make the call for this one. WDYT David? This one is good to go, but it'll go out with the virtualbox update, and therefore with the mga4 kernel update. Honestly, we could validate those too, and I was planning to this past weekend, but never found time to re-do my mga4 virtualbox testing. I guess it can wait a few more days. Once the Mageia 4 kernel advisory is updated and uploaded, this update can be pushed. (Yes, I meant Mageia 4, as that kernel, this one, and virtualbox, have to be pushed together.) Keywords:
(none) =>
validated_update An update for this issue has been pushed to Mageia Updates repository. http://advisories.mageia.org/MGASA-2014-0454.html Status:
NEW =>
RESOLVED |