| Summary: | Update request: kernel-4.14.70-2.mga6 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Thomas Backlund <tmb> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, brtians1, fri, jim, sysadmin-bugs, tarazed25, westel, wilcal.int |
| Version: | 6 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | mga6-64-ok, mga6-32-ok | ||
| Source RPM: | kernel | CVE: | |
| Status comment: | |||
|
Description
Thomas Backlund
2018-09-16 15:34:42 CEST
Mageia 6, x86_64 Installed on Intel Core i7-4790 (-HT-MCP-) workstation with NVIDIA GeForce GTX 970. Mate desktop running normally. No problems apparent. Virtualbox works. CC:
(none) =>
tarazed25 on mga6-64 kernel-desktop plasma
packages installed cleanly:
- cpupower-4.14.70-1.mga6.x86_64
- kernel-desktop-4.14.70-1.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-4.14.70-1.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-latest-4.14.70-1.mga6.x86_64
- kernel-desktop-latest-4.14.70-1.mga6.x86_64
- kernel-userspace-headers-4.14.70-1.mga6.x86_64
- virtualbox-kernel-4.14.70-desktop-1.mga6-5.2.18-5.mga6.x86_64
- virtualbox-kernel-desktop-latest-5.2.18-5.mga6.x86_64
system rebooted normally:
$ uname -r
4.14.70-desktop-1.mga6
common applications OK
vbox and clients launched normally
Updated to kernel-desktop-4.14.70-1 on mga6-64 and mga6-32 clients - no regressions
OK for mga6-64 on this system:
Machine: Device: desktop System: Dell product: Precision Tower 3620
Mobo: Dell model: 09WH54 v: A00 UEFI [Legacy]: Dell v: 2.11.0
CPU: Quad core Intel Core i7-6700 (-HT-MCP-)
Graphics: Card: Intel HD Graphics 530CC:
(none) =>
jim On mga6-32 kernel-server xfce packages installed cleanly: - cpupower-4.14.70-1.mga6.i586 - kernel-server-4.14.70-1.mga6-1-1.mga6.i586 - kernel-server-devel-4.14.70-1.mga6-1-1.mga6.i586 - kernel-server-devel-latest-4.14.70-1.mga6.i586 - kernel-server-latest-4.14.70-1.mga6.i586 - kernel-userspace-headers-4.14.70-1.mga6.i586 system re-booted normally: $ uname -r 4.14.70-server-1.mga6 # dkms status nvidia-current, 390.87-1.mga6.nonfree, 4.14.70-server-1.mga6, i586: installed Common applications OK kernel-server-4.14.70-1 OK for mga6-32 on this system: Machine: Device: desktop Mobo: ECS model: GeForce7050M-M v: 1.0 CPU: Quad core AMD Phenom 9500 (-MCP-) cache: 2048 KB Graphics: Card: NVIDIA GK208B [GeForce GT 710] on mga6-64 kernel-desktop xfce Machine: Device: desktop Mobo: ECS model: GeForce7050M-M v: 1.0 CPU: Quad core AMD Phenom 9500 (-MCP-) cache: 2048 KB Graphics: Card: NVIDIA GK208B [GeForce GT 710] packages installed cleanly: - cpupower-4.14.70-1.mga6.x86_64 - kernel-desktop-4.14.70-1.mga6-1-1.mga6.x86_64 - kernel-desktop-devel-4.14.70-1.mga6-1-1.mga6.x86_64 - kernel-desktop-devel-latest-4.14.70-1.mga6.x86_64 - kernel-desktop-latest-4.14.70-1.mga6.x86_64 - kernel-userspace-headers-4.14.70-1.mga6.x86_64 system rebooted normally: $ uname -r 4.14.70-desktop-1.mga6 # dkms status nvidia-current, 390.87-1.mga6.nonfree, 4.14.70-desktop-1.mga6, x86_64: installed common applications OK OK for mga6-64 on this system Desktop version running fine on 64-bit workstation with i7 Core CPUs and NVIDIA GTX 770. Network file server. Stress tests completed OK. Leaving it to run for a while. Four OK 64 bit quick tests as was done for 4.14.69: Machines updated to all updates in all updates_testing repos incl kernel-desktop-4.14.70-1.mga6-1-1.mga6.x86_64.rpm , quick test + continue to be used, three of them daily: --- 64 bit OK on my workstation: i7-2600K, Nvidia GTX760 (GK104) using proprietary driver GeForce 420 and later, with CUDA & OpenCL detected OK in BOINC, LVM on LUKS on SSD, VirtualBox running MSW7, Plasma5.12 etc, video in Firefox,,, --- 64 bit OK on laptop Thinkpad T61, with Nvidia GPU proprietary driver, LVM on SSD. Updated to all updates in all updates_testing repos. All installed cleanly Resume from suspend is OK incl wifi and video in firefox resumes but sound go missing on the video until i restart firefox. (as with previous kernel - possibly the problem lies elsewhere...) This one is running MATE, all other are Plasma dektops. --- 64 bit OK on laptop Thinkpad T60, CPU core2Duo T5600, ati RV515/M54 X1400, wifi AR5418, LVM on LUKS on SSD. Tested OK Resume from suspend and hibernation is OK incl wifi and video in firefox. --- 64 bit OK on laptop Acer Aspire 7 A717-71G: Intel i5, Nvidia and Intel GPU:s but only intel is configured, as per default in Mageia installer. Disk: nVME SSD, EFI boot, separate /boot, then rest of system in LVM lv:s in a LUKS encrypted pv. Suspend-resume incl wifi etc works. Have no time now to test if it still fail hibernate-resume, Bug 22804 (have never worked for me) CC:
(none) =>
fri x2-3800 AMD - Nvidia 6150le (304 driver or nouveau). $ uname -a Linux localhost 4.14.70-desktop-1.mga6 #1 SMP Sat Sep 15 21:50:59 UTC 2018 i686 i686 i686 GNU/Linux following 6 packages are going to be installed: - cpupower-4.14.70-1.mga6.i586 - cpupower-devel-4.14.70-1.mga6.i586 - kernel-desktop-4.14.70-1.mga6-1-1.mga6.i586 - kernel-desktop-devel-4.14.70-1.mga6-1-1.mga6.i586 - kernel-desktop-devel-latest-4.14.70-1.mga6.i586 - kernel-desktop-latest-4.14.70-1.mga6.i586 97MB of additional disk space will be used. 62MB of packages will be retrieved. System booted to a working desktop, browser works, web-server is working CC:
(none) =>
brtians1 On real hardware, M6, Plasma, 64-bit
initial install:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
kernel-desktop-devel-latest dkms-nvidia-current cpupower
[root@localhost wilcal]# uname -a
Linux localhost 4.14.69-desktop-1.mga6 #1 SMP Wed Sep 12 10:35:26 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.69-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-5.2.18-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.2.18-3.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-5.2.18-1.mga6.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-5.2.18-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-5.2.18-3.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.2.18-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi kernel-desktop-devel-latest
Package kernel-desktop-devel-latest-4.14.69-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-nvidia-current
Package dkms-nvidia-current-390.87-1.mga6.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.69-1.mga6.x86_64 is already installed
[root@localhost wilcal]# lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
Subsystem: Gigabyte Technology Co., Ltd Device 3518
Kernel driver in use: nvidia
Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current
Using: Mageia-6-LiveDVD-Xfce-i586-DVD.iso
Create a Vbox client. Works just fine. Boots to a working desktop.
install from update_testing:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
kernel-desktop-devel-latest dkms-nvidia-current cpupower
The following 9 packages are going to be installed:
- cpupower-4.14.70-1.mga6.x86_64
- kernel-desktop-4.14.70-1.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-4.14.70-1.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-latest-4.14.70-1.mga6.x86_64
- kernel-desktop-latest-4.14.70-1.mga6.x86_64
- vboxadditions-kernel-4.14.70-desktop-1.mga6-5.2.18-5.mga6.x86_64
- vboxadditions-kernel-desktop-latest-5.2.18-5.mga6.x86_64
- virtualbox-kernel-4.14.70-desktop-1.mga6-5.2.18-5.mga6.x86_64
- virtualbox-kernel-desktop-latest-5.2.18-5.mga6.x86_64
[root@localhost wilcal]# uname -a
Linux localhost 4.14.70-desktop-1.mga6 #1 SMP Sat Sep 15 20:23:19 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.70-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-5.2.18-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.2.18-5.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-5.2.18-1.mga6.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-5.2.18-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-5.2.18-5.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.2.18-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi kernel-desktop-devel-latest
Package kernel-desktop-devel-latest-4.14.70-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-nvidia-current
Package dkms-nvidia-current-390.87-1.mga6.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.70-1.mga6.x86_64 is already installed
[wilcal@localhost ~]$ lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
Subsystem: Gigabyte Technology Co., Ltd Device 3518
Kernel driver in use: nvidia
Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current
Mageia-6-LiveDVD-Xfce-i586-DVD.iso
Still works as a Vbox client. Boots to a working desktop.
Mageia-6-LiveDVD-GNOME-x86_64-DVD.iso
Create a Vbox client. Works just fine. Boots to a working desktop.
Mageia-6-x86_64-DVD.iso
Installs as a Vbox client. Boots to a working desktop.
Updates then reboots back to a working desktop.
Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)CC:
(none) =>
wilcal.int In a Vbox client, M6, Mate, 32-bit Testing: kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower [root@localhost wilcal]# uname -a Linux localhost 4.14.69-desktop-1.mga6 #1 SMP Wed Sep 12 10:18:08 UTC 2018 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.14.69-1.mga6.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.2.18-3.mga6.i586 is already installed [root@localhost wilcal]# urpmi cpupower Package cpupower-4.14.69-1.mga6.i586 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. Install kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower from updates testing Reboot system. [root@localhost wilcal]# uname -a Linux localhost 4.14.70-desktop-1.mga6 #1 SMP Sat Sep 15 21:50:59 UTC 2018 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.14.70-1.mga6.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.2.18-5.mga6.i586 is already installed [root@localhost wilcal]# urpmi cpupower Package cpupower-4.14.70-1.mga6.i586 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. In a Vbox client, M6, Mate, 64-bit Testing: kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower [root@localhost wilcal]# uname -a Linux localhost 4.14.65-desktop-1.mga6 #1 SMP Sat Aug 18 14:50:29 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.14.65-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.2.18-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi cpupower Package cpupower-4.14.65-1.mga6.x86_64 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. Install kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower from updates testing The following 5 packages are going to be installed: - cpupower-4.14.70-1.mga6.x86_64 - kernel-desktop-4.14.70-1.mga6-1-1.mga6.x86_64 - kernel-desktop-latest-4.14.70-1.mga6.x86_64 - vboxadditions-kernel-4.14.70-desktop-1.mga6-5.2.18-5.mga6.x86_64 - vboxadditions-kernel-desktop-latest-5.2.18-5.mga6.x86_64 Reboot system. [root@localhost wilcal]# uname -a Linux localhost 4.14.70-desktop-1.mga6 #1 SMP Sat Sep 15 20:23:19 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.14.70-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.2.18-5.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi cpupower Package cpupower-4.14.70-1.mga6.x86_64 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. Real hardware, Dell Inspiron 5100, 32-bit P4, 1GB RAM, Radeon 7500 graphics, Atheros wifi, newly-installed 32-bit Xfce system, using the desktop586 kernel. Packages installed cleanly. Did a cold boot, tried several apps. Everything looks good. CC:
(none) =>
andrewsfarm Mageia 6, x86_64 Aorus X5 laptop Intel Core i7-5700HQ (-HT-MCP-) NVIDIA GM204M [GeForce GTX 965M] Rebooted to the Mate desktop. All running OK. The system recovers immediately after closing and opening the lid. So as notified on QA meeting last night, respinning theese to get a potential local exploit fixed... I also picked up a couple of kernel crashers, and a better fix for the interrupt storm on Ryzen platforms..., all changes since -1.mga6: - drm: fix use of freed memory in drm_mode_setcrtc - drm/i915: Apply the GTT write flush for all !llc machines - mm: get rid of vmacache_flush_all() entirely (CVE-2018-17182) - net/tls: Set count of SG entries if sk_alloc_sg returns -ENOSPC - pinctrl/amd: only handle irq if it is pending and unmasked So just check they still boot and we'll flush them out SRPMS: kernel-4.14.70-2.mga6.src.rpm kernel-userspace-headers-4.14.70-2.mga6.src.rpm kmod-vboxadditions-5.2.18-6.mga6.src.rpm kmod-virtualbox-5.2.18-6.mga6.src.rpm kmod-xtables-addons-2.13-66.mga6.src.rpm i586: cpupower-4.14.70-2.mga6.i586.rpm cpupower-devel-4.14.70-2.mga6.i586.rpm kernel-desktop-4.14.70-2.mga6-1-1.mga6.i586.rpm kernel-desktop586-4.14.70-2.mga6-1-1.mga6.i586.rpm kernel-desktop586-devel-4.14.70-2.mga6-1-1.mga6.i586.rpm kernel-desktop586-devel-latest-4.14.70-2.mga6.i586.rpm kernel-desktop586-latest-4.14.70-2.mga6.i586.rpm kernel-desktop-devel-4.14.70-2.mga6-1-1.mga6.i586.rpm kernel-desktop-devel-latest-4.14.70-2.mga6.i586.rpm kernel-desktop-latest-4.14.70-2.mga6.i586.rpm kernel-doc-4.14.70-2.mga6.noarch.rpm kernel-server-4.14.70-2.mga6-1-1.mga6.i586.rpm kernel-server-devel-4.14.70-2.mga6-1-1.mga6.i586.rpm kernel-server-devel-latest-4.14.70-2.mga6.i586.rpm kernel-server-latest-4.14.70-2.mga6.i586.rpm kernel-source-4.14.70-2.mga6-1-1.mga6.noarch.rpm kernel-source-latest-4.14.70-2.mga6.noarch.rpm kernel-userspace-headers-4.14.70-2.mga6.i586.rpm perf-4.14.70-2.mga6.i586.rpm vboxadditions-kernel-4.14.70-desktop-2.mga6-5.2.18-6.mga6.i586.rpm vboxadditions-kernel-4.14.70-desktop586-2.mga6-5.2.18-6.mga6.i586.rpm vboxadditions-kernel-4.14.70-server-2.mga6-5.2.18-6.mga6.i586.rpm vboxadditions-kernel-desktop586-latest-5.2.18-6.mga6.i586.rpm vboxadditions-kernel-desktop-latest-5.2.18-6.mga6.i586.rpm vboxadditions-kernel-server-latest-5.2.18-6.mga6.i586.rpm virtualbox-kernel-4.14.70-desktop-2.mga6-5.2.18-6.mga6.i586.rpm virtualbox-kernel-4.14.70-desktop586-2.mga6-5.2.18-6.mga6.i586.rpm virtualbox-kernel-4.14.70-server-2.mga6-5.2.18-6.mga6.i586.rpm virtualbox-kernel-desktop586-latest-5.2.18-6.mga6.i586.rpm virtualbox-kernel-desktop-latest-5.2.18-6.mga6.i586.rpm virtualbox-kernel-server-latest-5.2.18-6.mga6.i586.rpm xtables-addons-kernel-4.14.70-desktop-2.mga6-2.13-66.mga6.i586.rpm xtables-addons-kernel-4.14.70-desktop586-2.mga6-2.13-66.mga6.i586.rpm xtables-addons-kernel-4.14.70-server-2.mga6-2.13-66.mga6.i586.rpm xtables-addons-kernel-desktop586-latest-2.13-66.mga6.i586.rpm xtables-addons-kernel-desktop-latest-2.13-66.mga6.i586.rpm xtables-addons-kernel-server-latest-2.13-66.mga6.i586.rpm x86_64: cpupower-4.14.70-2.mga6.x86_64.rpm cpupower-devel-4.14.70-2.mga6.x86_64.rpm kernel-desktop-4.14.70-2.mga6-1-1.mga6.x86_64.rpm kernel-desktop-devel-4.14.70-2.mga6-1-1.mga6.x86_64.rpm kernel-desktop-devel-latest-4.14.70-2.mga6.x86_64.rpm kernel-desktop-latest-4.14.70-2.mga6.x86_64.rpm kernel-doc-4.14.70-2.mga6.noarch.rpm kernel-server-4.14.70-2.mga6-1-1.mga6.x86_64.rpm kernel-server-devel-4.14.70-2.mga6-1-1.mga6.x86_64.rpm kernel-server-devel-latest-4.14.70-2.mga6.x86_64.rpm kernel-server-latest-4.14.70-2.mga6.x86_64.rpm kernel-source-4.14.70-2.mga6-1-1.mga6.noarch.rpm kernel-source-latest-4.14.70-2.mga6.noarch.rpm kernel-userspace-headers-4.14.70-2.mga6.x86_64.rpm perf-4.14.70-2.mga6.x86_64.rpm vboxadditions-kernel-4.14.70-desktop-2.mga6-5.2.18-6.mga6.x86_64.rpm vboxadditions-kernel-4.14.70-server-2.mga6-5.2.18-6.mga6.x86_64.rpm vboxadditions-kernel-desktop-latest-5.2.18-6.mga6.x86_64.rpm vboxadditions-kernel-server-latest-5.2.18-6.mga6.x86_64.rpm virtualbox-kernel-4.14.70-desktop-2.mga6-5.2.18-6.mga6.x86_64.rpm virtualbox-kernel-4.14.70-server-2.mga6-5.2.18-6.mga6.x86_64.rpm virtualbox-kernel-desktop-latest-5.2.18-6.mga6.x86_64.rpm virtualbox-kernel-server-latest-5.2.18-6.mga6.x86_64.rpm xtables-addons-kernel-4.14.70-desktop-2.mga6-2.13-66.mga6.x86_64.rpm xtables-addons-kernel-4.14.70-server-2.mga6-2.13-66.mga6.x86_64.rpm xtables-addons-kernel-desktop-latest-2.13-66.mga6.x86_64.rpm xtables-addons-kernel-server-latest-2.13-66.mga6.x86_64.rpm Summary:
Update request: kernel-4.14.70-1.mga6 =>
Update request: kernel-4.14.70-2.mga6 on mga6-64 kernel-desktop plasma
packages installed cleanly:
- cpupower-4.14.70-2.mga6.x86_64
- kernel-desktop-4.14.70-2.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-4.14.70-2.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-latest-4.14.70-2.mga6.x86_64
- kernel-desktop-latest-4.14.70-2.mga6.x86_64
- kernel-userspace-headers-4.14.70-2.mga6.x86_64
- virtualbox-kernel-4.14.70-desktop-2.mga6-5.2.18-6.mga6.x86_64
- virtualbox-kernel-desktop-latest-5.2.18-6.mga6.x86_64
system rebooted normally:
$ uname -r
4.14.70-desktop-2.mga6
vbox and clients launched normally
Updated to kernel-desktop-4.14.70-2 on mga6-64 and mga6-32 clients - both relaunched normally
OK for mga6-64 on this system:
Machine: Device: desktop System: Dell product: Precision Tower 3620
Mobo: Dell model: 09WH54 v: A00 UEFI [Legacy]: Dell v: 2.11.0
CPU: Quad core Intel Core i7-6700 (-HT-MCP-)
Graphics: Card: Intel HD Graphics 530
on mga6-64 kernel-desktop xfce Machine: Device: desktop Mobo: ECS model: GeForce7050M-M v: 1.0 CPU: Quad core AMD Phenom 9500 (-MCP-) cache: 2048 KB Graphics: Card: NVIDIA GK208B [GeForce GT 710] packages installed cleanly: - cpupower-4.14.70-2.mga6.x86_64 - kernel-desktop-4.14.70-2.mga6-1-1.mga6.x86_64 - kernel-desktop-devel-4.14.70-2.mga6-1-1.mga6.x86_64 - kernel-desktop-devel-latest-4.14.70-2.mga6.x86_64 - kernel-desktop-latest-4.14.70-2.mga6.x86_64 - kernel-userspace-headers-4.14.70-2.mga6.x86_64 system rebooted normally: $ uname -r 4.14.70-desktop-2.mga6 # dkms status nvidia-current, 390.87-1.mga6.nonfree, 4.14.70-desktop-2.mga6, x86_64: installed OK for mga6-64 on this system On mga6-32 kernel-server xfce packages installed cleanly: - cpupower-4.14.70-2.mga6.i586 - kernel-server-4.14.70-2.mga6-1-1.mga6.i586 - kernel-server-devel-4.14.70-2.mga6-1-1.mga6.i586 - kernel-server-devel-latest-4.14.70-2.mga6.i586 - kernel-server-latest-4.14.70-2.mga6.i586 - kernel-userspace-headers-4.14.70-2.mga6.i586 system re-booted normally: $ uname -r 4.14.70-server-2.mga6 # dkms status nvidia-current, 390.87-1.mga6.nonfree, 4.14.70-server-2.mga6, i586: installed kernel-server-4.14.70-2 OK for mga6-32 on this system: Machine: Device: desktop Mobo: ECS model: GeForce7050M-M v: 1.0 CPU: Quad core AMD Phenom 9500 (-MCP-) cache: 2048 KB Graphics: Card: NVIDIA GK208B [GeForce GT 710]
Advisory, added to svn:
type: security
subject: Updated kernel packages fix security vulnerabilities
CVE:
- CVE-2018-5391
- CVE-2018-14641
- CVE-2018-17182
src:
6:
core:
- kernel-4.14.70-2.mga6
- kernel-userspace-headers-4.14.70-2.mga6
- kmod-vboxadditions-5.2.18-6.mga6
- kmod-virtualbox-5.2.18-6.mga6
- kmod-xtables-addons-2.13-66.mga6
description: |
This kernel update is based on the upstream 4.14.70 and adds additional
fixes for the L1TF security issues.tre security issues. It also fixes
atleast the following security issues:
Linux kernel from versions 3.9 and up, is vulnerable to a denial of
service attack with low rates of specially modified packets targeting IP
fragment re-assembly. An attacker may cause a denial of service condition
by sending specially crafted IP fragments (CVE-2018-5391, FragmentSmack).
A security flaw was found in the ip_frag_reasm() function in
net/ipv4/ip_fragment.c in the Linux kernel caused by fixes for
CVE-2018-5391, which can cause a later system crash in ip_do_fragment().
With certain non-default, but non-rare, configuration of a victim host,
an attacker can trigger this crash remotely, thus leading to a remote
denial-of-service (CVE-2018-14641).
An issue was discovered in the Linux kernel through 4.18.8. The
vmacache_flush_all function in mm/vmacache.c mishandles sequence number
overflows. An attacker can trigger a use-after-free (and possibly gain
privileges) via certain thread creation, map, unmap, invalidation, and
dereference operations (CVE-2018-17182).
Other fixes in this update:
* drm: fix use of freed memory in drm_mode_setcrtc
* drm/i915: Apply the GTT write flush for all !llc machines
* net/tls: Set count of SG entries if sk_alloc_sg returns -ENOSPC
(fixes a kernel crash)
* pinctrl/amd: only handle irq if it is pending and unmasked
(possible real fix for the interrupt storm on Ryzen platform)
For other uptstream fixes in this update, see the referenced changelog.
references:
- https://bugs.mageia.org/show_bug.cgi?id=23586
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.70Keywords:
(none) =>
advisory Fixed advisory first part to state: This kernel update is based on the upstream 4.14.70 and adds additional fixes for the L1TF security issues. It also fixes atleast the following security issues: Mageia 6, x86_64 Intel Core i7-4790 (-HT-MCP-) NVIDIA GM204 [GeForce GTX 970] Installed all, including server packages. Rebooted desktop kernel. $ sudo dkms status nvidia-current, 390.87-1.mga6.nonfree, 4.14.69-desktop-1.mga6, x86_64: installed [...] xtables-addons, 2.13-3.mga6, 4.14.70-desktop-2.mga6, x86_64: installed-binary from 4.14.70-desktop-2.mga6 $ uname -r 4.14.70-desktop-2.mga6 Mate running fine. Removed some older kernels and ran update-grub2. Stress tests completed OK. Networking OK. So far so good. x86_64 Running fine here on Intel Core i7-2600 (-HT-MCP-) NVIDIA GF114 [GeForce GTX 555] Mate desktop, stress tests, wifi networking. GPU reaching 87°C during glmark2. Scheduled updates and created a 9 GB tar file and copied that to a USB drive. Mga6 on real 32bit hardware desktop(lxde/lxqt DE system)
uname -r
4.14.68-desktop-1.mga6
$ lscpu
Architecture: i686
CPU op-mode(s): 32-bit
AMD Athlon(tm) XP 2400+
Flags: fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge
mca cmov pat pse36 mmx fxsr sse syscall mmxext 3dnowext
3dnow cpuid 3dnowprefetch vmmcall
To satisfy dependencies, the following packages are going to be installed:
Package Version Release Arch
(medium "Core Updates Testing (distrib5)")
cpupower 4.14.70 2.mga6 i586
kernel-desktop-4.14.70-2.mga6 1 1.mga6 i586
kernel-desktop-devel-4.14.70-> 1 1.mga6 i586
kernel-desktop-devel-latest 4.14.70 2.mga6 i586
kernel-desktop-latest 4.14.70 2.mga6 i586
kernel-userspace-headers 4.14.70 2.mga6 i586
perf 4.14.70 2.mga6 i586
Proceed with the installation of the 7 packages? (Y/n) y
reboot
uname -r
4.14.70-desktop-2.mga6
firefox -ok
USB detected
VLC play audio and video file (.mp4) from USB okCC:
(none) =>
westel Mageia 6, x86_64 Desktop kernel packages installed. Rebooted to Mate. All looks good on this machine. Deca core Intel Core i9-7900X (-HT-MCP-) NVIDIA GP102 [GeForce GTX 1080 Ti] Mageia infra is now running on kernel-server-4.14.70-2.mga6 Real hardware, HP Probook 6550b, i3, 8GB, Intel graphics, Intel wifi, 64-bit Plasma system using the desktop kernel. Installed new kernel last evening, used it this morning to read an online newspaper, check Facebook, download a file, shop for a new laptop battery. No regressions noted. Four OK 64 bit quick tests as was done for -1 @ comment 6. However: some problem with v4l, i have not tested recently until now. Do USB video cameras work for other here? Plugging in my USB microscope journalctl -f give: sep 22 16:16:29 svarten kernel: usb 1-1.2: new high-speed USB device number 20 using ehci-pci sep 22 16:16:29 svarten kernel: usb 1-1.2: New USB device found, idVendor=0c45, idProduct=62e0 sep 22 16:16:29 svarten kernel: usb 1-1.2: New USB device strings: Mfr=2, Product=1, SerialNumber=0 sep 22 16:16:29 svarten kernel: usb 1-1.2: Product: USB 2.0 Camera sep 22 16:16:29 svarten kernel: usb 1-1.2: Manufacturer: Sonix Technology Co., Ltd. sep 22 16:16:29 svarten kernel: uvcvideo: Found UVC 1.00 device USB 2.0 Camera (0c45:62e0) sep 22 16:16:30 svarten kernel: uvcvideo 1-1.2:1.0: Entity type for entity Extension 5 was not initialized! sep 22 16:16:30 svarten kernel: uvcvideo 1-1.2:1.0: Entity type for entity Extension 4 was not initialized! sep 22 16:16:30 svarten kernel: uvcvideo 1-1.2:1.0: Entity type for entity Processing 3 was not initialized! sep 22 16:16:30 svarten kernel: uvcvideo 1-1.2:1.0: Entity type for entity Camera 1 was not initialized! sep 22 16:16:30 svarten kernel: input: USB 2.0 Camera: USB Camera as /devices/pci0000:00/0000:00:1a.0/usb1/1-1/1-1.2/1-1.2:1.0/input/input24 sep 22 16:16:30 svarten kernel: usb 1-1.2: 3:1: cannot get freq at ep 0x84 sep 22 16:16:30 svarten kernel: usb 1-1.2: Warning! Unlikely big volume range (=3328), cval->res is probably wrong. sep 22 16:16:30 svarten kernel: usb 1-1.2: [2] FU [Mic Capture Volume] ch = 1, val = 4608/7936/1 sep 22 16:16:30 svarten mtp-probe[985]: checking bus 1, device 20: "/sys/devices/pci0000:00/0000:00:1a.0/usb1/1-1/1-1.2" sep 22 16:16:30 svarten mtp-probe[985]: bus: 1, device: 20 was not an MTP device sep 22 16:16:30 svarten dolphin[4553]: QObject::connect: invalid null parameter sep 22 16:16:30 svarten dolphin[4553]: QObject::connect: invalid null parameter sep 22 16:16:30 svarten kdeinit5[3791]: QObject::connect: invalid null parameter sep 22 16:16:30 svarten dolphin[4553]: QObject::connect: invalid null parameter sep 22 16:16:30 svarten dolphin[4553]: QObject::connect: invalid null parameter sep 22 16:16:30 svarten kernel: usb 1-1.2: 3:1: cannot get freq at ep 0x84 sep 22 16:16:30 svarten kdeinit5[3791]: QObject::connect: invalid null parameter sep 22 16:16:30 svarten dolphin[4553]: QObject::connect: invalid null parameter sep 22 16:16:30 svarten dolphin[4553]: QObject::connect: invalid null parameter sep 22 16:16:30 svarten kdeinit5[3791]: QObject::connect: invalid null parameter sep 22 16:16:30 svarten kernel: usb 1-1.2: 3:1: cannot get freq at ep 0x84 ... and i.e neither guvcview nor luvcview find any device. On none test it worked a couple seconds sep 22 16:23:57 svarten kernel: usb 1-1.2: new full-speed USB device number 25 using ehci-pci sep 22 16:23:57 svarten kernel: usb 1-1.2: device descriptor read/64, error -32 sep 22 16:23:58 svarten kernel: usb 1-1.2: device descriptor read/64, error -32 sep 22 16:23:58 svarten kernel: usb 1-1.2: new high-speed USB device number 26 using ehci-pci sep 22 16:23:58 svarten kernel: usb 1-1-port2: attempt power cycle sep 22 16:23:59 svarten kernel: usb 1-1.2: new full-speed USB device number 27 using ehci-pci sep 22 16:23:59 svarten kernel: usb 1-1.2: device not accepting address 27, error -32 sep 22 16:23:59 svarten kernel: usb 1-1.2: new full-speed USB device number 28 using ehci-pci sep 22 16:24:00 svarten kernel: usb 1-1.2: device not accepting address 28, error -32 sep 22 16:24:00 svarten kernel: usb 1-1-port2: unable to enumerate USB device This worked some months ago in same PC, Mageia install, and USB device... s /none/one Ah, that camera/cable is glitchy... old and worn. System works nicely with two other USB video devices i found in my drawers. Sorry about the noise. All OK :) MGA6-64 Physical hardware: AMD Athlon(tm) II X3 450 Processor RS780L [Radeon 3000] Installed cpu, kernel-desktop Seems to be working as designed. On real hardware, M6, Plasma, 64-bit
initial install:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
kernel-desktop-devel-latest dkms-nvidia-current cpupower
The following 10 packages are going to be installed:
- dkms-virtualbox-5.2.18-1.mga6.noarch
- vboxadditions-kernel-4.14.69-desktop-1.mga6-5.2.18-3.mga6.x86_64
- vboxadditions-kernel-desktop-latest-5.2.18-3.mga6.x86_64
- virtualbox-5.2.18-1.mga6.x86_64
- virtualbox-doc-5.1.30-1.mga6.noarch
- virtualbox-guest-additions-5.2.18-1.mga6.x86_64
- virtualbox-kernel-4.14.69-desktop-1.mga6-5.2.18-3.mga6.x86_64
- virtualbox-kernel-desktop-latest-5.2.18-3.mga6.x86_64
- x11-driver-video-vboxvideo-5.2.18-1.mga6.x86_64
- xrandr-1.5.0-1.mga6.x86_64
[root@localhost wilcal]# uname -a
Linux localhost 4.14.69-desktop-1.mga6 #1 SMP Wed Sep 12 10:35:26 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.69-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-5.2.18-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.2.18-3.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-5.2.18-1.mga6.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-5.2.18-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-5.2.18-3.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.2.18-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi kernel-desktop-devel-latest
Package kernel-desktop-devel-latest-4.14.69-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-nvidia-current
Package dkms-nvidia-current-390.87-1.mga6.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.69-1.mga6.x86_64 is already installed
[root@localhost wilcal]# lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
Subsystem: Gigabyte Technology Co., Ltd Device 3518
Kernel driver in use: nvidia
Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current
Using: Mageia-6-LiveDVD-Xfce-i586-DVD.iso
Create a Vbox client. Works just fine. Boots to a working desktop.
install from update_testing:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
kernel-desktop-devel-latest dkms-nvidia-current cpupower
The following 7 packages are going to be installed:
- cpupower-4.14.70-2.mga6.x86_64
- kernel-desktop-4.14.70-2.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-4.14.70-2.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-latest-4.14.70-2.mga6.x86_64
- kernel-desktop-latest-4.14.70-2.mga6.x86_64
- vboxadditions-kernel-4.14.70-desktop-2.mga6-5.2.18-6.mga6.x86_64
- vboxadditions-kernel-desktop-latest-5.2.18-6.mga6.x86_64The following 7 packages are going to be installed:
[root@localhost wilcal]# uname -a
Linux localhost 4.14.70-desktop-2.mga6 #1 SMP Thu Sep 20 22:05:46 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.70-2.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-5.2.18-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.2.18-6.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-5.2.18-1.mga6.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-5.2.18-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-5.2.18-6.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.2.18-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi kernel-desktop-devel-latest
Package kernel-desktop-devel-latest-4.14.70-2.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-nvidia-current
Package dkms-nvidia-current-390.87-1.mga6.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.70-2.mga6.x86_64 is already installed
[wilcal@localhost ~]$ lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
Subsystem: Gigabyte Technology Co., Ltd Device 3518
Kernel driver in use: nvidia
Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current
Mageia-6-LiveDVD-Xfce-i586-DVD.iso
Still works as a Vbox client. Boots to a working desktop.
Mageia-6-LiveDVD-GNOME-x86_64-DVD.iso
Create a Vbox client. Works just fine. Boots to a working desktop.
Mageia-6.1-LiveDVD-Plasma-x86_64-DVD.iso
Installs as a Vbox client. Boots to a working desktop.
Updates then reboots back to a working desktop.
Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)
Enough tests, validating... Keywords:
(none) =>
validated_update An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2018-0391.html Resolution:
(none) =>
FIXED |