| Summary: | Update request: kernel-4.14.104-2.mga6 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Thomas Backlund <tmb> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, brtians1, fri, herman.viaene, jim, sysadmin-bugs, tarazed25, westel, wilcal.int |
| Version: | 6 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA6-32-OK MGA6-64-OK | ||
| Source RPM: | kernel | CVE: | |
| Status comment: | |||
|
Description
Thomas Backlund
2019-02-27 23:58:04 CET
x86_64 server kernel is now in use on Mageia infra In a Vbox client, M6, Mate, 32-bit Testing: kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower [root@localhost wilcal]# uname -a Linux localhost 4.14.100-desktop-1.mga6 #1 SMP Fri Feb 15 08:58:09 UTC 2019 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.14.100-1.mga6.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.2.24-4.mga6.i586 is already installed [root@localhost wilcal]# urpmi cpupower Package cpupower-4.14.100-1.mga6.i586 is already installed Install kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower from updates testing The following 6 packages are going to be installed: - cpupower-4.14.104-2.mga6.i586 - kernel-desktop-4.14.104-2.mga6-1-1.mga6.i586 - kernel-desktop-latest-4.14.104-2.mga6.i586 - meta-task-6-3.3.mga6.noarch - vboxadditions-kernel-4.14.104-desktop-2.mga6-5.2.24-8.mga6.i586 - vboxadditions-kernel-desktop-latest-5.2.24-8.mga6.i586 Reboot system. [root@localhost wilcal]# uname -a Linux localhost 4.14.104-desktop-2.mga6 #1 SMP Wed Feb 27 18:52:18 UTC 2019 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.14.104-2.mga6.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.2.24-8.mga6.i586 is already installed [root@localhost wilcal]# urpmi cpupower Package cpupower-4.14.104-2.mga6.i586 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. CC:
(none) =>
wilcal.int In a Vbox client, M6, Mate, 64-bit Testing: kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower [root@localhost wilcal]# uname -a Linux localhost 4.14.100-desktop-1.mga6 #1 SMP Fri Feb 15 09:29:46 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.14.100-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.2.24-4.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi cpupower Package cpupower-4.14.100-1.mga6.x86_64 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. Install kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower from updates testing The following 6 packages are going to be installed: - cpupower-4.14.104-2.mga6.x86_64 - kernel-desktop-4.14.104-2.mga6-1-1.mga6.x86_64 - kernel-desktop-latest-4.14.104-2.mga6.x86_64 - meta-task-6-3.3.mga6.noarch - vboxadditions-kernel-4.14.104-desktop-2.mga6-5.2.24-8.mga6.x86_64 - vboxadditions-kernel-desktop-latest-5.2.24-8.mga6.x86_64 Reboot system. [root@localhost wilcal]# uname -a Linux localhost 4.14.104-desktop-2.mga6 #1 SMP Wed Feb 27 17:08:11 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.14.104-2.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.2.24-8.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi cpupower Package cpupower-4.14.104-2.mga6.x86_64 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. Hardware - Intel core i3-2100, laptop
>>gnome<<
The following 5 packages are going to be installed:
- aria2-1.25.0-1.1.mga6.x86_64
- cpupower-4.14.104-2.mga6.x86_64
- kernel-desktop-4.14.104-2.mga6-1-1.mga6.x86_64
- kernel-desktop-latest-4.14.104-2.mga6.x86_64
- meta-task-6-3.3.mga6.noarch
I've installed the update and rebooted.
Libreoffice working
Firefox working
no memory leak issues that I can tell, its been on for a few hours
Suspends and wakes-up without issue
Working as expected.CC:
(none) =>
brtians1 on mga6-64 kernel-desktop plasma
packages installed cleanly:
- cpupower-4.14.104-2.mga6.x86_64
- kernel-desktop-4.14.104-2.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-4.14.104-2.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-latest-4.14.104-2.mga6.x86_64
- kernel-desktop-latest-4.14.104-2.mga6.x86_64
- kernel-userspace-headers-4.14.104-2.mga6.x86_64
- virtualbox-kernel-4.14.104-desktop-2.mga6-5.2.24-8.mga6.x86_64
- virtualbox-kernel-desktop-latest-5.2.24-8.mga6.x86_64
system rebooted normally:
$ uname -r
4.14.104-desktop-2.mga6
# dkms status
virtualbox, 5.2.24-1.mga6, 4.14.104-desktop-2.mga6, x86_64: installed
virtualbox, 5.2.24-1.mga6, 4.14.104-desktop-2.mga6, x86_64: installed-binary from 4.14.104-desktop-2.mga6
vbox and clients launched normally
Updated to 4.14.104-desktop on mga6-64 (plasma) and mga6-32 (plasma) clients - both relaunched normally.
winxp and win7 vbox clients re-launched normally
no regressions noted
OK for mga6-64 on this system:
Machine: Device: desktop System: Dell product: Precision Tower 3620
Mobo: Dell model: 09WH54 v: A00 UEFI [Legacy]: Dell v: 2.11.0
CPU: Quad core Intel Core i7-6700 (-HT-MCP-)
Graphics: Card: Intel HD Graphics 530CC:
(none) =>
jim On mga6-32 kernel-server xfce packages installed cleanly: - cpupower-4.14.104-2.mga6.i586 - kernel-server-4.14.104-2.mga6-1-1.mga6.i586 - kernel-server-devel-4.14.104-2.mga6-1-1.mga6.i586 - kernel-server-devel-latest-4.14.104-2.mga6.i586 - kernel-server-latest-4.14.104-2.mga6.i586 - kernel-userspace-headers-4.14.104-2.mga6.i586 system re-booted normally: $ uname -r 4.14.104-server-2.mga6 # dkms status nvidia-current, 390.87-1.mga6.nonfree, 4.14.104-server-2.mga6, i586: installed no regressions noted OK for mga6-32 on this system: Machine: Device: desktop Mobo: ECS model: GeForce7050M-M v: 1.0 CPU: Quad core AMD Phenom 9500 (-MCP-) cache: 2048 KB Graphics: Card: NVIDIA GK208B [GeForce GT 710] kernel 4.14.104-desktop-2 on five x86_64 Intel/nvidia machines All tested with Mate desktop: Poseidon core i7 4790 nvidia GTX970 : 390.87 : DP, 4K monitor Celestia and Stellarium work. Dino PC core i7 4790K nvidia GTX770 : 410.78 : HDMI, 3K monitor Not expecting that nvidia driver. * User is logged out after a period of inactivity. stellarium aborts. Aorus X5 laptop core i7 5700HQ nvidia GTX965M : 390.87 : 3K monitor Suspend and recover works fine when lid is closed and reopened. Alienware X51 - legacy boot core i7 2600 nvidia GTX555 : 390.87 : DVI, 3K monitor stellarium aborts. Scan 3XS core i9 9700X Decacore nvidia GTX1080Ti : 390.87 : DVI, 3K monitor celestia and stellarium work. ------------------------------------------------------------------------------ General remarks. Updated from desktop 4.14.100 The nvidia graphics driver was built and installed without any problem. All rebooted to desktop under nvidia-current. NFS shares mounted OK. In these latest kernels there are always a couple of popups after login requiring the root password to enable networking and set rfkill state. So far the Mate desktop is running fine apart from stellarium, and stress tests complete OK. No problems with virtualbox. celestia needs a bug report for mga6 - it works after a local rebuild, so not a kernel problem. When stellarium misbehaves it seems to be a GL problem so may not be relevant. Continuing with random tests. CC:
(none) =>
tarazed25 Referring to comment 7: Installed powertop on the Aorus X5 laptop and let it run for a few minutes and interacted a bit. A number of items were listed as Bad but I am not going to worry about that. Seems to work alright anyway. Battery at 94%. (In reply to Len Lawrence from comment #8) > Referring to comment 7: > > Installed powertop on the Aorus X5 laptop and let it run for a few minutes > and interacted a bit. > > A number of items were listed as Bad but I am not going to worry about that. > Seems to work alright anyway. Battery at 94%. Yep, with 4.14.100 powertop would simply segfault at startup: https://bugs.mageia.org/show_bug.cgi?id=24426 So that it starts / reports something is an improvement :) On real hardware, M6.1, Plasma, 64-bit
initial install:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
kernel-desktop-devel-latest dkms-nvidia-current cpupower
The following 10 packages are going to be installed:
- dkms-virtualbox-5.2.24-1.mga6.noarch
- vboxadditions-kernel-4.14.100-desktop-1.mga6-5.2.24-4.mga6.x86_64
- vboxadditions-kernel-desktop-latest-5.2.24-4.mga6.x86_64
- virtualbox-5.2.24-1.mga6.x86_64
- virtualbox-doc-5.2.24-1.mga6.noarch
- virtualbox-guest-additions-5.2.24-1.mga6.x86_64
- virtualbox-kernel-4.14.100-desktop-1.mga6-5.2.24-4.mga6.x86_64
- virtualbox-kernel-desktop-latest-5.2.24-4.mga6.x86_64
- x11-driver-video-vboxvideo-5.2.24-1.mga6.x86_64
- xrandr-1.5.0-1.mga6.x86_64
[root@localhost wilcal]# uname -a
Linux localhost 4.14.100-desktop-1.mga6 #1 SMP Fri Feb 15 09:29:46 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.100-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-5.2.24-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.2.24-4.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-5.2.24-1.mga6.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-5.2.24-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-5.2.24-4.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.2.24-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi kernel-desktop-devel-latest
Package kernel-desktop-devel-latest-4.14.100-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-nvidia-current
Package dkms-nvidia-current-390.87-1.mga6.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.100-1.mga6.x86_64 is already installed
[root@localhost wilcal]# lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
Subsystem: Gigabyte Technology Co., Ltd Device 3518
Kernel driver in use: nvidia
Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current
Using: Mageia-7-beta2-Live-Xfce-i586.iso
Create a Vbox client. Works just fine. Boots to a working desktop.
install from update_testing:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
kernel-desktop-devel-latest dkms-nvidia-current cpupower
The following 10 packages are going to be installed:
- cpupower-4.14.104-2.mga6.x86_64
- kernel-desktop-4.14.104-2.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-4.14.104-2.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-latest-4.14.104-2.mga6.x86_64
- kernel-desktop-latest-4.14.104-2.mga6.x86_64
- meta-task-6-3.3.mga6.noarch
- vboxadditions-kernel-4.14.104-desktop-2.mga6-5.2.24-8.mga6.x86_64
- vboxadditions-kernel-desktop-latest-5.2.24-8.mga6.x86_64
- virtualbox-kernel-4.14.104-desktop-2.mga6-5.2.24-8.mga6.x86_64
- virtualbox-kernel-desktop-latest-5.2.24-8.mga6.x86_64
[root@localhost wilcal]# uname -a
Linux localhost 4.14.104-desktop-2.mga6 #1 SMP Wed Feb 27 17:08:11 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.104-2.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-5.2.24-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.2.24-8.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-5.2.24-1.mga6.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-5.2.24-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-5.2.24-8.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.2.24-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi kernel-desktop-devel-latest
Package kernel-desktop-devel-latest-4.14.104-2.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-nvidia-current
Package dkms-nvidia-current-390.87-1.mga6.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.104-2.mga6.x86_64 is already installed
[wilcal@localhost ~]$ lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
Subsystem: Gigabyte Technology Co., Ltd Device 3518
Kernel driver in use: nvidia
Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current
Mageia-7-beta2-Live-Xfce-i586.iso
Still works as a Vbox client. Boots to a working desktop.
Mageia-6.1-LiveDVD-GNOME-x86_64-DVD.iso
Create a Vbox client. Works just fine. Boots to a working desktop.
Mageia-7-beta2-x86_64.iso
Installs as a Vbox client. Boots to a working desktop.
Updates then reboots back to a working desktop.
Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)
Real hardware, Athlon X2 7750, 8GB RAM, nvidia 9800GT graphics (nvidia340 driver), Atheros wifi. 64-bit Plasma system, running the server kernel. The following 8 packages are going to be installed: - cpupower-4.14.104-2.mga6.x86_64 - kernel-server-4.14.104-2.mga6-1-1.mga6.x86_64 - kernel-server-devel-4.14.104-2.mga6-1-1.mga6.x86_64 - kernel-server-devel-latest-4.14.104-2.mga6.x86_64 - kernel-server-latest-4.14.104-2.mga6.x86_64 - kernel-userspace-headers-4.14.104-2.mga6.x86_64 - virtualbox-kernel-4.14.104-server-2.mga6-5.2.24-8.mga6.x86_64 - virtualbox-kernel-server-latest-5.2.24-8.mga6.x86_64 All packages installed cleanly. I'm assuming the nvidia kernel module built correctly, because everything looks good after the reboot. Tried several apps. Using it now to make this report. 64-bit server kernel OK on this hardware. CC:
(none) =>
andrewsfarm (In reply to Thomas Backlund from comment #0) > Security and bugfixes... What about those of us using kernel-4.18.20-desktop-1.mga6? Is there any plan to move us to the kernel 4.19 branch? mga6, x86_64, Mate The server kernel is working fine here for a core i7 4790 machine with nvidia GTX970 graphics card, driver 390.87. Switched from the desktop kernel to 4.14.104-server-2. Ran stress tests as well. Leaving it to run - main QA testing machine. MGA6-32 MATE on IBM Thinkpad R50e Installed kernel and xtables. Internet wifi OK, access to NFS shares, odt, ods , xlsx files, mpeg, txt, odp files all OK, but no sound. I get: # lsmod | grep snd snd_intel8x0 36864 4 snd_intel8x0m 20480 1 snd_ac97_codec 106496 2 snd_intel8x0m,snd_intel8x0 ac97_bus 16384 1 snd_ac97_codec snd_pcm 106496 4 snd_intel8x0m,snd_ac97_codec,snd_intel8x0 snd_timer 28672 1 snd_pcm snd 69632 17 snd_intel8x0m,snd_ac97_codec,snd_timer,thinkpad_acpi,snd_intel8x0,snd_pcm soundcore 16384 1 snd and that looks normal as do the settings in MATE, no mute set. CC:
(none) =>
herman.viaene After closing one window (Firefox) the whole desktop is unresponsive. I had to Crtl-Alt-F2 to give the reboot command. Further using this kernel for testing bug 24178 reveals no problems anymore. Except for the sound, the laptop remains dead silent. Mga6 on real 32bit hardware desktop(lxde/lxqt DE system)
uname -r
4.14.100-desktop-1.mga6
$ lscpu
Architecture: i686
CPU op-mode(s): 32-bit
AMD Athlon(tm) XP 2400+
Flags: fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge
mca cmov pat pse36 mmx fxsr sse syscall mmxext 3dnowext
3dnow cpuid 3dnowprefetch vmmcall
To satisfy dependencies, the following packages are going to be installed:
Package Version Release Arch
(medium "Core Updates Testing (distrib5)")
cpupower 4.14.104 2.mga6 i586
kernel-desktop-4.14.104-2.mga6 1 1.mga6 i586
kernel-desktop-latest 4.14.104 2.mga6 i586
kernel-userspace-headers 4.14.104 2.mga6 i586
57MB of additional disk space will be used.
53MB of packages will be retrieved.
Proceed with the installation of the 4 packages? (Y/n) y
reboot
uname -r
4.14.104-desktop-2.mga6
firefox -ok
USB thumbdrive detected and pcmanfm popup
VLC playback of .mkv from USB ok, Audio and Video -okCC:
(none) =>
westel Mageia6, x86_64 3XS Intel Core i9-7900X (-HT-MCP-) GeForce GTX 1080 Ti/PCIe/SSE2 4.6.0 NVIDIA 390.87 RAM 32 GB Disk storage: /dev/sda ATA Samsung SSD 860 232GB /dev/sdb WD4005FZBX-0 3.6TB /home nvme 931GB Switched from the 4.14.104-desktop-2.mga6 kernel to 4.14.104-server-2.mga6. Rebooted without fuss to the Mate desktop with NFS shares mounted. $ stress -c 13 -t 30 $ stress -m 4 -t 30 $ stress -i 4 -t 30 $ stress -d 4 -t 30 Watched these operations in gkrellm. Desktop applications working fine including sound and video. Recovered an unfinished document in LibreOffice and saved it. So far so good - letting it run. Have been running it since it appeared in testing... two weeks. No issues seen. 64 bit, plasma, Nvidia. BOINC, Libreoffice, Firefox. Virtualbox running MSW7. CC:
(none) =>
fri
Advisory, added to svn:
type: security
subject: Updated kernel packages fix security vulnerability
CVE:
- CVE-2018-1000026
src:
6:
core:
- kernel-4.14.104-2.mga6
- kernel-userspace-headers-4.14.104-2.mga6
- kmod-vboxadditions-5.2.24-8.mga6
- kmod-virtualbox-5.2.24-8.mga6
- kmod-xtables-addons-2.13-82.mga6
description: |
This kernel update is based on the upstream 4.14.104 and fixes atleast
the following security issue:
Linux Linux kernel version at least v4.8 onwards, probably well before
contains a Insufficient input validation vulnerability in bnx2x network
card driver that can result in DoS: Network card firmware assertion takes
card off-line. This attack appear to be exploitable via An attacker on a
must pass a very large, specially crafted packet to the bnx2x card.
This can be done from an untrusted guest VM (CVE-2018-1000026).
It also fixes signal handling issues causing powertop to crash and some
tracing tools to fail on execve tests.
For other uptstream fixes in this update, see the referenced changelogs.
references:
- https://bugs.mageia.org/show_bug.cgi?id=24440
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.101
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.102
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.103
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.104Keywords:
(none) =>
advisory, validated_update An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2019-0107.html Resolution:
(none) =>
FIXED |