| Summary: | Update request: kernel-4.4.79-1.mga5 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Thomas Backlund <tmb> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | brtians1, jim, mageia, sysadmin-bugs, tarazed25, wilcal.int |
| Version: | 5 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | advisory mga5-64-ok mga5-32-ok | ||
| Source RPM: | kernel | CVE: | |
| Status comment: | |||
| Bug Depends on: | |||
| Bug Blocks: | 21325 | ||
|
Description
Thomas Backlund
2017-07-28 18:56:10 CEST
Thomas Backlund
2017-07-28 19:03:38 CEST
Blocks:
(none) =>
21325 $ uname -a Linux localhost 4.4.79-desktop-1.mga5 #1 SMP Fri Jul 28 02:50:06 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux Video Card: RS780L [Radeon 3000] When I boot up the machine with 4.4.79 updates using default option, it is running in text mode versus showing the normal start-up image. Otherwise, seems to be working okay so far. --- this was installed --- The following 6 packages are going to be installed: - kernel-desktop-4.4.79-1.mga5-1-1.mga5.x86_64 - kernel-desktop-latest-4.4.79-1.mga5.x86_64 - vboxadditions-kernel-4.4.79-desktop-1.mga5-5.1.22-8.mga5.x86_64 - vboxadditions-kernel-desktop-latest-5.1.22-8.mga5.x86_64 - virtualbox-kernel-4.4.79-desktop-1.mga5-5.1.22-8.mga5.x86_64 - virtualbox-kernel-desktop-latest-5.1.22-8.mga5.x86_64 54MB of additional disk space will be used. 48MB of packages will be retrieved. ---- I will continue to test. CC:
(none) =>
brtians1 In a Vbox client, M5.1, KDE, 32-bit Testing: kernel-desktop-latest vboxadditions-kernel-desktop-latest [root@localhost wilcal]# uname -a Linux localhost 4.4.74-desktop-1.mga5 #1 SMP Mon Jun 26 08:33:18 UTC 2017 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.4.74-1.mga5.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.22-7.mga5.i586 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. Installed kernel-desktop-latest vboxadditions-kernel-desktop-latest from updates testing Reboot client [root@localhost wilcal]# uname -a Linux localhost 4.4.79-desktop-1.mga5 #1 SMP Fri Jul 28 02:02:29 UTC 2017 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.4.79-1.mga5.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.22-8.mga5.i586 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. CC:
(none) =>
wilcal.int In a Vbox client, M5.1, KDE, 64bit Testing: kernel-desktop-latest vboxadditions-kernel-desktop-latest [root@localhost wilcal]# uname -a Linux localhost 4.4.74-desktop-1.mga5 #1 SMP Mon Jun 26 07:50:58 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.4.74-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.22-7.mga5.x86_64 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. Installed kernel-desktop-latest vboxadditions-kernel-desktop-latest from updates testing Reboot client [root@localhost wilcal]# uname -a Linux localhost 4.4.79-desktop-1.mga5 #1 SMP Fri Jul 28 02:50:06 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.4.79-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.22-8.mga5.x86_64 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. On mga5-64 packages installed cleanly: - cpupower-4.4.79-1.mga5.x86_64 - kernel-desktop-4.4.79-1.mga5-1-1.mga5.x86_64 - kernel-desktop-latest-4.4.79-1.mga5.x86_64 - virtualbox-kernel-4.4.79-desktop-1.mga5-5.1.22-8.mga5.x86_64 - virtualbox-kernel-desktop-latest-5.1.22-8.mga5.x86_64 system rebooted normally $ uname -r 4.4.79-desktop-1.mga5 no rgressions noted virtualbox launched normally OK for mga5-64 on this system: Dell product: Precision Tower 3620 Mobo: Dell model: 09WH54 Card: Intel HD Graphics 530 CPU: Quad core Intel Core i7-6700 (-HT-MCP-) CC:
(none) =>
jim On mga5-32 in a vbox VM packages installed cleanly: - cpupower-4.4.79-1.mga5.i586 - kernel-desktop-4.4.79-1.mga5-1-1.mga5.i586 - kernel-desktop-latest-4.4.79-1.mga5.i586 - kernel-userspace-headers-4.4.79-1.mga5.i586 - vboxadditions-kernel-4.4.79-desktop-1.mga5-5.1.22-8.mga5.i586 - vboxadditions-kernel-desktop-latest-5.1.22-8.mga5.i586 - kernel-desktop-devel-4.4.79-1.mga5-1-1.mga5.i586 - kernel-desktop-devel-latest-4.4.79-1.mga5.i586 System re-booted normally $ uname -r 4.4.79-desktop-1.mga5 no regressions noted OK for mga5-32 in a vbox VM No issues on physical hardware AMD/ATI Radeon. Other than boot-up screen mentioned prior. Sleeping and recovering appropriately. Working as designed. Intel(R) Core(TM) i3 CPU M 350 @ 2.27GHz $ uname -a Linux localhost.localdomain 4.4.79-desktop-1.mga5 #1 SMP Fri Jul 28 02:02:29 UTC 2017 i686 i686 i686 GNU/Linux physical hardware install. The following 8 packages are going to be installed: - kernel-desktop-4.4.79-1.mga5-1-1.mga5.i586 - kernel-desktop-latest-4.4.79-1.mga5.i586 - vboxadditions-kernel-4.4.79-desktop-1.mga5-5.1.22-8.mga5.i586 - vboxadditions-kernel-desktop-latest-5.1.22-8.mga5.i586 - virtualbox-guest-additions-5.1.26-1.mga5.i586 - virtualbox-kernel-4.4.79-desktop-1.mga5-5.1.22-8.mga5.i586 - virtualbox-kernel-desktop-latest-5.1.22-8.mga5.i586 - x11-driver-video-vboxvideo-5.1.26-1.mga5.i586 53MB of additional disk space will be used. 49MB of packages will be retrieved. Is it ok to continue? -- rebooted system appears to be working as designed. Will continue testing laptop. x86_64 Aorus X5 laptop : Intel(R) Core(TM) i7-5700HQ CPU @ 2.70GHz 2 x nvidia GeForce GTX 965M : 16GB RAM Installed these for mga5 - KDE4 - EFI boot - cpupower-4.4.79-1.mga5.x86_64 - kernel-desktop-4.4.79-1.mga5-1-1.mga5.x86_64 - kernel-desktop-devel-4.4.79-1.mga5-1-1.mga5.x86_64 - kernel-desktop-devel-latest-4.4.79-1.mga5.x86_64 - kernel-desktop-latest-4.4.79-1.mga5.x86_64 - kernel-userspace-headers-4.4.79-1.mga5.x86_64 - rpm -qa | grep perf-4.4.55-1.mga5 - xtables-addons-kernel-desktop-latest-2.10-44.mga5 - xtables-addons-kernel-4.4.79-desktop-1.mga5-2.10-44.mga5 $ uname -r 4.4.79-desktop-1.mga5 KDE running fine. Checked dolphin, LO writer, ruby, tk, networking, NFS shares, vlc - sound and video. firefox. image display, emacs, vi, stress. All OK so far. CC:
(none) =>
tarazed25 Re comment 8. Suspend and resume worked. Fans working normally. Able to continue an open emacs session. Installed, booted and is running for the past 10 hours without issues. Many applications, including OpenGL and vdpau using ones, tested without any regressions noticed. System: x86_64, Plasma, nVidia card using proprietary driver. $ uname -a Linux marte 4.4.79-desktop-1.mga5 #1 SMP Fri Jul 28 02:50:06 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux $ lspci | grep VGA 01:00.0 VGA compatible controller: NVIDIA Corporation GT218 [GeForce 210] (rev a2) $ rpm -qa | grep kernel.*4.4.79 | sort kernel-desktop-4.4.79-1.mga5-1-1.mga5 kernel-desktop-devel-4.4.79-1.mga5-1-1.mga5 kernel-desktop-devel-latest-4.4.79-1.mga5 kernel-desktop-latest-4.4.79-1.mga5 kernel-userspace-headers-4.4.79-1.mga5 CC:
(none) =>
mageia Installed on VirtualBox VM, booted and is running without issues. Several applications tested without any regressions noticed. Host system: x86_64, Plasma, nVidia card using proprietary driver. Guest system: x86_64, Plasma, xbox additions, VirtualBox Xorg driver with desktop resize working. # uname -a Linux vbox-marte 4.4.79-desktop-1.mga5 #1 SMP Fri Jul 28 02:50:06 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux # rpm -qa | grep kernel.*4.4.79 | sort kernel-desktop-4.4.79-1.mga5-1-1.mga5 kernel-desktop-latest-4.4.79-1.mga5 kernel-userspace-headers-4.4.79-1.mga5 vboxadditions-kernel-4.4.79-desktop-1.mga5-5.1.22-8.mga5 mga5 x86_64 EFI multiboot : nvidia GTX 970 MSI motherboard Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz 32GB RAM MageiaUpdate - cpupower-4.4.79-1.mga5.x86_64 - kernel-desktop-4.4.79-1.mga5-1-1.mga5.x86_64 - kernel-desktop-devel-4.4.79-1.mga5-1-1.mga5.x86_64 - kernel-desktop-devel-latest-4.4.79-1.mga5.x86_64 - kernel-desktop-latest-4.4.79-1.mga5.x86_64 - kernel-userspace-headers-4.4.79-1.mga5.x86_64 nvidia-current installed Installed "manually" - kernel-doc - perf - xtables-addons-kernel-desktop-latest - xtables-addons-kernel-4.4.79-desktop-1.mga5 - virtualbox-kernel-desktop-latest - virtualbox-kernel-4.4.79-desktop-1.mga5 - kernel-source-latest - kernel-source-4.4.79-1.mga5 Ran drakboot. Rebooted as the default kernel to Mate desktop. $ uname -r 4.4.79-desktop-1.mga5 nvidia 375.66 cpu stress test raised temperature to 72°C, dropped back to 37° afterwards. Tried a few desktop operations: firefox, emacs, thunar, LO writer, mplayer video, pavucontrol to check pulseaudio. Shared directory automounted. ssh remote login - played video using vlc (jerky and no sound). All good. Addendum to comment 12 Installed virtualbox and dkms-virtualbox. Successful launch of vbox session running kernel 4.4.68-desktop586-1-mga5.
subject: Updated kernel packages fixes security and other bugs
CVE:
- CVE-2017-10810
src:
5:
core:
- kernel-4.4.79-1.mga5
- kernel-userspace-headers-4.4.79-1.mga5
- kmod-vboxadditions-5.1.22-8.mga5
- kmod-virtualbox-5.1.22-8.mga5
- kmod-xtables-addons-2.10-44.mga5
description: |
This kernel update is based on upstream 4.4.79 and fixes atleast the
following security issues:
Linux kernel built with the VirtIO GPU driver(CONFIG_DRM_VIRTIO_GPU) support
is vulnerable to a memory leakage issue. It could occur while creating a
virtio gpu object in virtio_gpu_object_create(). A user/process could use
this flaw to leak host kernel memory potentially resulting in Dos
(CVE-2017-10810).
It also contains followup fixes to the Stack Clash (CVE-2017-1000370,
CVE-2017-1000371) security issues resolved in kernels released at end
of June, 2017.
For other upstream fixes in this update, read the referenced changelogs.
references:
- https://bugs.mageia.org/show_bug.cgi?id=21390
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.75
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.76
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.77
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.78
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.79Whiteboard:
(none) =>
advisory On real hardware, M5.1, KDE, 64-bit
initial install:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
kernel-desktop-devel-latest nvidia-current-kernel-desktop-latest
[root@localhost wilcal]# uname -a
Linux localhost 4.4.79-desktop-1.mga5 #1 SMP Fri Jul 28 02:50:06 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.4.79-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-5.1.26-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.1.22-8.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-5.1.26-1.mga5.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-5.1.26-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-5.1.22-8.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.1.26-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi kernel-desktop-devel-latest
Package kernel-desktop-devel-latest-4.4.79-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi nvidia-current-kernel-desktop-latest
Package nvidia-current-kernel-desktop-latest-352.79-10.mga5.nonfree.x86_64 is already installed
[wilcal@localhost ~]$ lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
Subsystem: Gigabyte Technology Co., Ltd Device 3518
Kernel driver in use: nvidia
Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current
M5.1 i586 Gnome Live-CD runs as a Vbox client.
Boots to a working desktop. Common apps work.
Screen sizes are correct.
M6 x86_64 Plasma CI installs and runs as a Vbox client
Updates and reboots back to a working desktop.
Screen sizes are correct.
Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)
Looks good
In a Vbox client, M5.1, KDE, 32-bit Testing: kernel-desktop-latest vboxadditions-kernel-desktop-latest [root@localhost wilcal]# uname -a Linux localhost 4.4.74-desktop-1.mga5 #1 SMP Mon Jun 26 08:33:18 UTC 2017 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.4.74-1.mga5.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.22-7.mga5.i586 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. Installed kernel-desktop-latest vboxadditions-kernel-desktop-latest from updates testing Reboot client [root@localhost wilcal]# uname -a Linux localhost 4.4.79-desktop-1.mga5 #1 SMP Fri Jul 28 02:02:29 UTC 2017 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.4.79-1.mga5.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.22-8.mga5.i586 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. In a Vbox client, M5.1, KDE, 64bit Testing: kernel-desktop-latest vboxadditions-kernel-desktop-latest [root@localhost wilcal]# uname -a Linux localhost 4.4.74-desktop-1.mga5 #1 SMP Mon Jun 26 07:50:58 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.4.74-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.22-7.mga5.x86_64 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. Installed kernel-desktop-latest vboxadditions-kernel-desktop-latest from updates testing Reboot client [root@localhost wilcal]# uname -a Linux localhost 4.4.79-desktop-1.mga5 #1 SMP Fri Jul 28 02:50:06 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.4.79-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.22-8.mga5.x86_64 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. Adding the OKs from copious testing and Validating. Keywords:
(none) =>
validated_update
claire robinson
2017-08-03 19:25:37 CEST
Whiteboard:
advisory mga5-64-ok mga5-32 ok =>
advisory mga5-64-ok mga5-32-ok An update for this issue has been pushed to the Mageia Updates repository. http://advisories.mageia.org/MGASA-2017-0242.html Status:
NEW =>
RESOLVED |