| Summary: | Update request: kernel-4.1.15-1.mga5 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Thomas Backlund <tmb> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, brtians1, lists.jjorge, sysadmin-bugs, wilcal.int |
| Version: | 5 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA5-32-OK MGA5-64-OK advisory | ||
| Source RPM: | kernel | CVE: | |
| Status comment: | |||
| Bug Depends on: | |||
| Bug Blocks: | 17398 | ||
|
Description
Thomas Backlund
2015-12-25 13:38:30 CET
Thomas Backlund
2015-12-25 13:42:17 CET
Blocks:
(none) =>
17398 In VirtualBox, M5, KDE, 32-bit Package(s) under test: kernel-desktop586-latest vboxadditions-kernel-desktop586-latest default install of kernel-desktop586-latest [root@localhost wilcal]# uname -a Linux localhost 4.1.13-desktop586-2.mga5 #1 SMP Wed Nov 11 00:50:24 UTC 2015 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop586-latest Package kernel-desktop586-latest-4.1.13-2.mga5.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop586-latest Package vboxadditions-kernel-desktop586-latest-5.0.10-1.mga5.i586 is already installed System boots to a working desktop. Common apps work. Screen dimensions are correct. install kernel-desktop-latest from updates_testing [root@localhost wilcal]# uname -a Linux localhost 4.1.15-desktop586-1.mga5 #1 SMP Thu Dec 24 21:51:44 UTC 2015 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop586-latest Package kernel-desktop586-latest-4.1.15-1.mga5.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop586-latest Package vboxadditions-kernel-desktop586-latest-5.0.12-1.mga5.i586 is already installed System boots to a working desktop. Common apps work. Screen dimensions are correct. CC:
(none) =>
wilcal.int In VirtualBox, M5, KDE, 64-bit Package(s) under test: kernel-desktop-latest vboxadditions-kernel-desktop-latest default install of kernel-desktop-latest [root@localhost wilcal]# uname -a Linux localhost 4.1.13-desktop-2.mga5 #1 SMP Wed Nov 11 01:02:41 UTC 2015 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.1.13-2.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.0.10-1.mga5.x86_64 is already installed System boots to a working desktop. Common apps work. Screen dimensions are correct. install kernel-desktop-latest from updates_testing [root@localhost wilcal]# uname -a Linux localhost 4.1.15-desktop-1.mga5 #1 SMP Thu Dec 24 22:04:24 UTC 2015 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.1.15-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.0.12-1.mga5.x86_64 is already installed System boots to a working desktop. Common apps work. Screen dimensions are correct. On real hardware, M5, KDE, 64-bit
Package(s) under test:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
nvidia-current-kernel-desktop-latest
default install of:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
nvidia-current-kernel-desktop-latest
[root@localhost wilcal]# uname -a
Linux localhost.localdomain 4.1.13-desktop-2.mga5 #1 SMP Wed Nov 11 01:02:41 UTC 2015 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.1.13-2.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-5.0.10-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.0.10-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-5.0.10-1.mga5.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-5.0.10-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-5.0.10-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.0.10-1.mga5.x86_64 is already installed
Marking x11-driver-video-vboxvideo as manually installed, it won't be auto-orphaned
writing /var/lib/rpm/installed-through-deps.list
[root@localhost wilcal]# urpmi nvidia-current-kernel-desktop-latest
Package nvidia-current-kernel-desktop-latest-346.96-3.mga5.nonfree.x86_64 is already installed
[root@localhost wilcal]# lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
Subsystem: Gigabyte Technology Co., Ltd Device 3518
Kernel driver in use: nvidia
Kernel modules: nvidiafb, nouveau, nvidia_current
System boots to a working desktop. Common apps work. M4.1 i586 KDE Live-CD runs as a Vbox client.
M5 x86_64 Live-DVD installs, updates and runs as a Vbox client.
Screen sizes of the host and client are correct.
install:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
nvidia-current-kernel-desktop-latest
from updates_testing
[root@localhost wilcal]# uname -a
Linux localhost.localdomain 4.1.15-desktop-1.mga5 #1 SMP Thu Dec 24 22:04:24 UTC 2015 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.1.15-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-5.0.12-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.0.12-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-5.0.12-1.mga5.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-5.0.12-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-5.0.12-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.0.12-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi nvidia-current-kernel-desktop-latest
Package nvidia-current-kernel-desktop-latest-346.96-4.mga5.nonfree.x86_64 is already installed
[wilcal@localhost ~]$ lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
Subsystem: Gigabyte Technology Co., Ltd Device 3518
Kernel driver in use: nvidia
Kernel modules: nvidiafb, nouveau, nvidia_current
System boots to a working desktop. Common apps work. Previously created M4.1 i586 KDE Live-CD runs
as a Vbox client. Previously installed M5 Gnome x86_64 LiveDVD runs as a Vbox client.
M5 x86-64 Gnome Live-DVD runs as a Vbox client. M5 i586 Gnome Live-CD installs, updates and runs as
a Vbox client.
Screen sizes of the host and all clients are correct.
Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)
test on physical hardware older nvidia equipment - AMD processor (32 bit kernel) - owncloud working acceptably - Video working properly Linux localhost 4.1.15-desktop-1.mga5 #1 SMP Thu Dec 24 22:07:17 UTC 2015 i686 i686 i686 GNU/Linux # urpmi kernel-desktop-latest Package kernel-desktop-latest-4.1.15-1.mga5.i586 is already installed Running a couple of more tests - need to reboot. CC:
(none) =>
brtians1 [root@localhost brian]# urpmi nvidia304-kernel-desktop-latest Package nvidia304-kernel-desktop-latest-304.128-4.mga5.nonfree.i586 is already installed [root@localhost brian]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.1.15-1.mga5.i586 is already installed Ran mplayer - working fine. Patch installs - fine LibreOffice - working Firefox - working Seems to be working nominally. working fine in 64-bit as well. AMD CPU and RS780L [Radeon 3000] [root@localhost brian]# uname -a Linux localhost 4.1.15-server-1.mga5 #1 SMP Thu Dec 24 22:32:55 UTC 2015 x86_64 x86_64 x86_64 GNU/Linux [root@localhost brian]# urpmi kernel-server-latest Package kernel-server-latest-4.1.15-1.mga5.x86_64 is already installed [root@localhost brian]# system working ok Testing on mga5-64 (EFI)
Packages installed from testing:
- cpupower-4.1.15-1.mga5.x86_64
- kernel-desktop-4.1.15-1.mga5-1-1.mga5.x86_64
- kernel-desktop-latest-4.1.15-1.mga5.x86_64
- kernel-userspace-headers-4.1.15-1.mga5.x86_64
- virtualbox-kernel-4.1.15-desktop-1.mga5-5.0.12-1.mga5.x86_64
- virtualbox-kernel-desktop-latest-5.0.12-1.mga5.x86_64
Packages installed cleanly. System re-booted normally. No problems noted.
Virtualbox launched and XP VM runs normally.
Machine: System: Hewlett-Packard product: CQ2925EA v: 1.00
Mobo: PEGATRON model: 2AE2 v: 1.02 Bios: AMI v: 8.08 date: 08/31/2012
CPU: Dual core Intel Pentium G645T (-MCP-) cache: 3072 KB
Graphics: Card:Intel 810 and later:Intel 2nd Generation Core Processor
OK for mga5-64 on this system
Testing on mga5-64 (BIOS)
Packages installed from testing:
- cpupower-4.1.15-1.mga5.x86_64
- kernel-desktop-4.1.15-1.mga5-1-1.mga5.x86_64
- kernel-desktop-latest-4.1.15-1.mga5.x86_64
- kernel-userspace-headers-4.1.15-1.mga5.x86_64
- nvidia-current-kernel-4.1.15-desktop-1.mga5-346.96-4.mga5.nonfree.x86_64
- nvidia-current-kernel-desktop-latest-346.96-4.mga5.nonfree.x86_64
- kernel-desktop-devel-latest-4.1.15-1.mga5.x86_64
- kernel-desktop-devel-4.1.15-1.mga5-1-1.mga5.x86_64
Packages installed cleanly. System re-booted normally. No problems noted.
Machine: Mobo: ECS model: GeForce7050M-M v: 1.0 Bios: American Megatrends
CPU: Quad core AMD Phenom 9500 (-MCP-) cache: 2048 KB
Graphics: Card: NVIDIA GF108 [GeForce GT 630]
Display Server: X.Org 1.16.4 drivers: nvidia,v4l
OK for mga5-64 on this system
Testing on mga5-32
Packages installed from testing:
- cpupower-4.1.15-1.mga5.i586
- kernel-server-4.1.15-1.mga5-1-1.mga5.i586
- kernel-server-latest-4.1.15-1.mga5.i586
- kernel-userspace-headers-4.1.15-1.mga5.i586
- nvidia-current-kernel-4.1.15-server-1.mga5-346.96-4.mga5.nonfree.i586
- nvidia-current-kernel-server-latest-346.96-4.mga5.nonfree.i586
- kernel-server-devel-4.1.15-1.mga5-1-1.mga5.i586
- kernel-server-devel-latest-4.1.15-1.mga5.i586
Packages installed cleanly. System re-booted normally. No problems noted.
Machine: Mobo: ECS model: GeForce7050M-M v: 1.0 Bios: American Megatrends
CPU: Quad core AMD Phenom 9500 (-MCP-) cache: 2048 KB
Graphics: Card: NVIDIA GF108 [GeForce GT 630]
Display Server: X.Org 1.16.4 drivers: nvidia,v4l
OK for mga5-32 on this system
Testing mga5-32 Packages installed: - cpupower-4.1.15-1.mga5.i586 - kernel-desktop-4.1.15-1.mga5-1-1.mga5.i586 - kernel-desktop-latest-4.1.15-1.mga5.i586 (seems like there ought to have been more) Packages installed cleanly, no issues noted after reboot. Dell Dimension E310 Intel P4, onboard Intel graphics. CC:
(none) =>
andrewsfarm Testing mga5-64 Same hardware as Comment 10, 64-bit versions of the same three packages. Packages installed cleanly, no issues noted after the reboot Testing mga5-32 Old 2007 Laptop : - Intel Celeron M430 - IGP i945 - Wifi iwn39xx All is ok. CC:
(none) =>
lists.jjorge
José Jorge
2016-01-06 11:58:54 CET
Whiteboard:
(none) =>
MGA5-32-OK MGA5-64-OK Testing mga5 32-bit Packages installed: - cpupower-4.1.15-1.mga5.i586 - kernel-server-4.1.15-1.mga5-1-1.mga5.i586 - kernel-server-devel-4.1.15-1.mga5-1-1.mga5.i586 - kernel-server-devel-latest-4.1.15-1.mga5.i586 - kernel-server-latest-4.1.15-1.mga5.i586 - kernel-userspace-headers-4.1.15-1.mga5.i586 - nvidia340-kernel-4.1.15-server-1.mga5-340.93-4.mga5.nonfree.i586 - nvidia340-kernel-server-latest-340.93-4.mga5.nonfree.i586 Packages install cleanly, no issues seen after reboot. ASRock AM2+ motherboard, Athlon X2 7750 processor, 8GB RAM, nVidia 9800GT video card. Testing mga5 64-bit Packages installed: - cpupower-4.1.15-1.mga5.x86_64 - dkms-virtualbox-5.0.12-1.mga5.noarch - kernel-server-4.1.15-1.mga5-1-1.mga5.x86_64 - kernel-server-devel-4.1.15-1.mga5-1-1.mga5.x86_64 - kernel-server-devel-latest-4.1.15-1.mga5.x86_64 - kernel-server-latest-4.1.15-1.mga5.x86_64 - kernel-userspace-headers-4.1.15-1.mga5.x86_64 - nvidia340-kernel-4.1.15-server-1.mga5-340.93-4.mga5.nonfree.x86_64 - nvidia340-kernel-server-latest-340.93-4.mga5.nonfree.x86_64 - virtualbox-5.0.12-1.mga5.x86_64 - virtualbox-kernel-4.1.15-server-1.mga5-5.0.12-1.mga5.x86_64 - virtualbox-kernel-server-latest-5.0.12-1.mga5.x86_64 Packages install cleanly, no issues seen after reboot After reboot, Virtualbox Mageia 5 32-bit guest additions also updated. Seems to still function as expected. (In reply to Thomas Andrews from comment #13) > Testing mga5 32-bit > > Packages installed: > > - cpupower-4.1.15-1.mga5.i586 > - kernel-server-4.1.15-1.mga5-1-1.mga5.i586 > - kernel-server-devel-4.1.15-1.mga5-1-1.mga5.i586 > - kernel-server-devel-latest-4.1.15-1.mga5.i586 > - kernel-server-latest-4.1.15-1.mga5.i586 > - kernel-userspace-headers-4.1.15-1.mga5.i586 > - nvidia340-kernel-4.1.15-server-1.mga5-340.93-4.mga5.nonfree.i586 > - nvidia340-kernel-server-latest-340.93-4.mga5.nonfree.i586 > > Packages install cleanly, no issues seen after reboot. > > ASRock AM2+ motherboard, Athlon X2 7750 processor, 8GB RAM, nVidia 9800GT > video card. Installed VirtualBox on this machine and created a Mageia 5 guest, allocating the maximum RAM allowed. While the guest was running, I did other things to see how well the server kernel handled RAM usage above 4GB. All went well. If swap was being used, I didn't notice it. Works fine on Mageia 5 x86_64, kernel-desktop + nvidia-current through bumblebee (dkms-bbswitch works fine too). Advisory (also added to svn); This kernel update is based on upstream 4.1.15 longterm kernel and fixes the following security issues: The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound (CVE-2015-6937). The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 4.2.6 allows local users to cause a denial of service (OOPS) via crafted keyctl commands (CVE-2015-7872). The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application (CVE-2015-7884). The dgnc_mgmt_ioctl function in drivers/staging/dgnc/dgnc_mgmt.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application (CVE-2015-7885). Felix Wilhelm discovered a race condition in the Xen paravirtualized drivers which can cause double fetch vulnerabilities. An attacker in the paravirtualized guest could exploit this flaw to cause a denial of service (crash the host) or potentially execute arbitrary code on the host (CVE-2015-8550 / XSA-155). Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not perform sanity checks on the device's state. An attacker could exploit this flaw to cause a denial of service (NULL dereference) on the host (CVE-2015-8551 / XSA-157). Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not perform sanity checks on the device's state. An attacker could exploit this flaw to cause a denial of service by flooding the logging system with WARN() messages causing the initial domain to exhaust disk space (CVE-2015-8552 / XSA-157). The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application (CVE-2015-8660). For other fixes in this update, see the referenced changelogs. references: - https://bugs.mageia.org/show_bug.cgi?id=17397 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.14 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.15 Whiteboard:
MGA5-32-OK MGA5-64-OK =>
MGA5-32-OK MGA5-64-OK advisory Works fine everywhere, Mageia 5 i586. This is ready for validation. CC:
(none) =>
sysadmin-bugs An update for this issue has been pushed to Mageia Updates repository. http://advisories.mageia.org/MGASA-2016-0005.html Resolution:
(none) =>
FIXED |