| Summary: | Update request: kernel-4.14.116-1.mga6 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Thomas Backlund <tmb> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, brtians1, fri, herman.viaene, jim, mageia, sysadmin-bugs, tarazed25, westel, wilcal.int |
| Version: | 6 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA6-32-OK MGA6-64-OK | ||
| Source RPM: | kernel | CVE: | |
| Status comment: | |||
|
Description
Thomas Backlund
2019-05-05 11:28:57 CEST
Laptop Core i3-2100, Toshiba, classic bios - cpupower-4.14.116-1.mga6.i586 - kernel-desktop-4.14.116-1.mga6-1-1.mga6.i586 - kernel-desktop-latest-4.14.116-1.mga6.i586 - meta-task-6-3.3.mga6.noarch rebooted $ uname -a Linux localhost.localdomain 4.14.116-desktop-1.mga6 #1 SMP Sat May 4 11:27:34 UTC 2019 i686 i686 i686 GNU/Linux Firefox, Libreoffice, gimp work fine. Sleep mode seems to be working. works for me CC:
(none) =>
brtians1 on mga6-64 kernel-desktop plasma
packages installed cleanly:
- cpupower-4.14.116-1.mga6.x86_64
- kernel-desktop-4.14.116-1.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-4.14.116-1.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-latest-4.14.116-1.mga6.x86_64
- kernel-desktop-latest-4.14.116-1.mga6.x86_64
- kernel-userspace-headers-4.14.116-1.mga6.x86_64
- virtualbox-kernel-4.14.116-desktop-1.mga6-6.0.6-2.mga6.x86_64
- virtualbox-kernel-desktop-latest-6.0.6-2.mga6.x86_64
system rebooted normally:
$ uname -r
4.14.116-desktop-1.mga6
# dkms status
virtualbox, 6.0.6-1.mga6, 4.14.116-desktop-1.mga6, x86_64: installed
virtualbox, 6.0.6-1.mga6, 4.14.116-desktop-1.mga6, x86_64: installed-binary from 4.14.116-desktop-1.mga6
(also updated to kernel-desktop-4.14.116-1 in 32 bit and 64 bit vbox clients)
no regressions noted
looks OK for mga6-64 on this system:
Machine: Device: desktop System: Dell product: Precision Tower 3620
Mobo: Dell model: 09WH54 v: A00 UEFI [Legacy]: Dell v: 2.11.0
CPU: Quad core Intel Core i7-6700 (-HT-MCP-)
Graphics: Card: Intel HD Graphics 530CC:
(none) =>
jim Intel Core i7-4790 (-HT-MCP-) NVIDIA GM204 [GeForce GTX 970] : nvidia 390.87 Clean install. Mate desktop. Bluetooth audio working with vlc and mplayer. Launched mga5 i586 client in virtualbox. Ran stress tests and GPU intensive applications. All OK. CC:
(none) =>
tarazed25 AMD Athlon X2 7750, 8GB, nvidia340 graphics, Atheros wifi. 64-bit Plasma install, desktop kernel. Packages installed cleanly, rebooted to a working desktop. Common apps work, including VirtualBox. No issues noted. CC:
(none) =>
andrewsfarm Intel Core i9-7900X (-HT-MCP-) GeForce GTX 1080 Ti/PCIe/SSE2 Installed the desktop kernel - rebooted to Mate. nvidia 390.87 had been built at installation time, along with nvidia304 and nvidia340. Bluetooth is available but no devices could be found. NFS shares mounted. virtualbox client launched. Ran the usual stress tests and a few desktop applications. No problems. MGA6-32 MATE on IBM Thinkpad R50e Installing cpupower-4.14.116-1.mga6.i586.rpm kernel-desktop-4.14.116-1.mga6-1-1.mga6.i586.rpm kernel-desktop-latest-4.14.116-1.mga6.i586.rpm kernel-doc-4.14.116-1.mga6.noarch.rpm kernel-userspace-headers-4.14.116-1.mga6.i586.rpm perf-4.14.116-1.mga6.i586.rpm xtables-addons-kernel-4.14.116-desktop-1.mga6-2.13-84.mga6.i586.rpm xtables-addons-kernel-desktop-latest-2.13-84.mga6.i586.rpm wireguard-tools-0.0.20190406-1.mga6.i586.rpm CC:
(none) =>
herman.viaene After reboot, desktop seems OK. Tested usual suspects ods, odt, odp, tif, jpg, mpg, pdf. All looks OK. Access to remote nfs shares works as well. Internet access over LAN cable and over Wifi OK. mga6-64, i7, Nvidia GPU and driver, Plasma Have been using it since it appeared in testing, no issues seen. With all updates in testing, i7-2600K, Nvidia GTX760 (GK104) using proprietary driver GeForce 420 and later, with CUDA & OpenCL detected OK in BOINC, / & /home & swap in LVM on LUKS on SSD, Plasma, Thunderbird, LibreOffice6, video in Firefox, VirtualBox running MSW7 incl USB2 flash stick and concurrently all cores used by BOINC. CC:
(none) =>
fri Installed and tested without issues. OK for x86_64 on intel/nvidia hardware. System: Mageia 6, x86_64, Plasma DE, LXQt DE, Intel CPU Q9400, nVidia GPU Geforce 210 using nvidia240 proprietary driver. Tests included normal workstation work for 3 days with daily reboots and extra testing. No regressions noticed. $ uname -a Linux marte 4.14.116-desktop-1.mga6 #1 SMP Sat May 4 08:34:09 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux $ rpm -qa | grep 4.14.116 | sort cpupower-4.14.116-1.mga6 kernel-desktop-4.14.116-1.mga6-1-1.mga6 kernel-desktop-devel-4.14.116-1.mga6-1-1.mga6 kernel-desktop-devel-latest-4.14.116-1.mga6 kernel-desktop-latest-4.14.116-1.mga6 kernel-userspace-headers-4.14.116-1.mga6 perf-4.14.116-1.mga6 virtualbox-kernel-4.14.116-desktop-1.mga6-6.0.6-2.mga6 $ lspcidrake shpchp : Intel Corporation|82801JI (ICH10 Family) PCI Express Root Port 3 [BRIDGE_PCI] ehci_pci : Intel Corporation|82801JI (ICH10 Family) USB2 EHCI Controller #1 [SERIAL_USB] ehci_pci : Intel Corporation|82801JI (ICH10 Family) USB2 EHCI Controller #2 [SERIAL_USB] snd_hda_intel : NVIDIA Corporation|High Definition Audio Controller [MULTIMEDIA_AUDIO_DEV] (rev: a1) uhci_hcd : Intel Corporation|82801JI (ICH10 Family) USB UHCI Controller #1 [SERIAL_USB] uhci_hcd : Intel Corporation|82801JI (ICH10 Family) USB UHCI Controller #4 [SERIAL_USB] uhci_hcd : Intel Corporation|82801JI (ICH10 Family) USB UHCI Controller #3 [SERIAL_USB] uhci_hcd : Intel Corporation|82801JI (ICH10 Family) USB UHCI Controller #6 [SERIAL_USB] shpchp : Intel Corporation|82801JI (ICH10 Family) PCI Express Port 2 [BRIDGE_PCI] unknown : Intel Corporation|4 Series Chipset DRAM Controller [BRIDGE_HOST] (rev: 03) i2c_i801 : Intel Corporation|82801JI (ICH10 Family) SMBus Controller [SERIAL_SMBUS] unknown : Intel Corporation|82801 PCI Bridge [BRIDGE_PCI] (rev: 90) snd_hda_intel : Intel Corporation|82801JI (ICH10 Family) HD Audio Controller [MULTIMEDIA_AUDIO_DEV] Card:NVIDIA GeForce 8100 to GeForce 415: NVIDIA Corporation|GT218 [GeForce 210] [DISPLAY_VGA] (rev: a2) uhci_hcd : Intel Corporation|82801JI (ICH10 Family) USB UHCI Controller #2 [SERIAL_USB] shpchp : Intel Corporation|4 Series Chipset PCI Express Root Port [BRIDGE_PCI] (rev: 03) r8169 : Realtek Semiconductor Co., Ltd.|RTL8111/8168/8411 PCI Express Gigabit Ethernet Controller [NETWORK_ETHERNET] (rev: 02) lpc_ich : Intel Corporation|82801JIB (ICH10) LPC Interface Controller [BRIDGE_ISA] uhci_hcd : Intel Corporation|82801JI (ICH10 Family) USB UHCI Controller #5 [SERIAL_USB] shpchp : Intel Corporation|82801JI (ICH10 Family) PCI Express Root Port 1 [BRIDGE_PCI] unknown : Intel Corporation|82801JI (ICH10 Family) SATA AHCI Controller [STORAGE_SATA] pata_jmicron : JMicron Technology Corp.|JMB368 IDE controller [STORAGE_IDE] hub : Linux 4.14.116-desktop-1.mga6 ehci_hcd|EHCI Host Controller [Hub|Unused|Full speed (or root) hub] usb_storage : Lexar|USB Flash Drive [Mass Storage|SCSI|Bulk-Only] usb_storage : Generic|Mass Storage Device [Mass Storage|SCSI|Bulk-Only] hub : Linux 4.14.116-desktop-1.mga6 ehci_hcd|EHCI Host Controller [Hub|Unused|Full speed (or root) hub] hub : Genesys Logic, Inc.|USB2.0 Hub [Hub|Unused|Full speed (or root) hub] usbhid : Sunplus Technology Co., Ltd|USB Laser Wheel Mouse [Human Interface Device|Boot Interface Subclass|Mouse] hub : Linux 4.14.116-desktop-1.mga6 uhci_hcd|UHCI Host Controller [Hub|Unused|Full speed (or root) hub] hub : Linux 4.14.116-desktop-1.mga6 uhci_hcd|UHCI Host Controller [Hub|Unused|Full speed (or root) hub] hub : Linux 4.14.116-desktop-1.mga6 uhci_hcd|UHCI Host Controller [Hub|Unused|Full speed (or root) hub] hub : Linux 4.14.116-desktop-1.mga6 uhci_hcd|UHCI Host Controller [Hub|Unused|Full speed (or root) hub] Mouse:evdev : Logitech|USB Receiver [Human Interface Device|Boot Interface Subclass|Keyboard] hub : Linux 4.14.116-desktop-1.mga6 uhci_hcd|UHCI Host Controller [Hub|Unused|Full speed (or root) hub] hub : Linux 4.14.116-desktop-1.mga6 uhci_hcd|UHCI Host Controller [Hub|Unused|Full speed (or root) hub] hid_logitech : Logitech USB Receiver hid_logitech : Logitech USB Receiver hid_generic : USB Laser Wheel Mouse CC:
(none) =>
mageia In a Vbox client, M6, Mate, 32-bit Testing: kernel-desktop-latest vboxadditions-kernel-desktop-latest [root@localhost wilcal]# uname -a Linux localhost 5.0.5-desktop586-2.mga7 #1 SMP Fri Mar 29 20:37:06 UTC 2019 i686 i686 i386 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.14.106-1.mga6.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-6.0.6-1.mga6.i586 is already installed Install kernel-desktop-latest vboxadditions-kernel-desktop-latest from updates testing Reboot system [root@localhost wilcal]# uname -a Linux localhost 5.0.5-desktop586-2.mga7 #1 SMP Fri Mar 29 20:37:06 UTC 2019 i686 i686 i386 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.14.116-1.mga6.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-6.0.6-2.mga6.i586 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. CC:
(none) =>
wilcal.int In a Vbox client, M6, Mate, 64-bit Testing: kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower [root@localhost wilcal]# uname -a Linux localhost 4.14.106-desktop-1.mga6 #1 SMP Thu Mar 14 18:01:29 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.14.106-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-6.0.6-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi cpupower Package cpupower-4.14.106-1.mga6.x86_64 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. Install kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower from updates testing The following 6 packages are going to be installed: - cpupower-4.14.116-1.mga6.x86_64 - kernel-desktop-4.14.116-1.mga6-1-1.mga6.x86_64 - kernel-desktop-latest-4.14.116-1.mga6.x86_64 - meta-task-6-3.3.mga6.noarch - vboxadditions-kernel-4.14.116-desktop-1.mga6-6.0.6-2.mga6.x86_64 - vboxadditions-kernel-desktop-latest-6.0.6-2.mga6.x86_64 Reboot system. [root@localhost wilcal]# uname -a Linux localhost 4.14.116-desktop-1.mga6 #1 SMP Sat May 4 08:34:09 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.14.116-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-6.0.6-2.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi cpupower Package cpupower-4.14.116-1.mga6.x86_64 is already installed Boots to a working desktop. Screen resolution is correct. Common apps work. On real hardware, M6.1, Plasma, 64-bit
initial install:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
kernel-desktop-devel-latest dkms-nvidia-current cpupower
The following 10 packages are going to be installed:
- dkms-virtualbox-6.0.6-1.mga6.noarch
- vboxadditions-kernel-4.14.106-desktop-1.mga6-6.0.6-1.mga6.x86_64
- vboxadditions-kernel-desktop-latest-6.0.6-1.mga6.x86_64
- virtualbox-6.0.6-1.mga6.x86_64
- virtualbox-doc-5.2.24-1.mga6.noarch
- virtualbox-guest-additions-6.0.6-1.mga6.x86_64
- virtualbox-kernel-4.14.106-desktop-1.mga6-6.0.6-1.mga6.x86_64
- virtualbox-kernel-desktop-latest-6.0.6-1.mga6.x86_64
- x11-driver-video-vboxvideo-5.2.24-1.mga6.x86_64
- xrandr-1.5.0-1.mga6.x86_64
[root@localhost wilcal]# uname -a
Linux localhost 4.14.106-desktop-1.mga6 #1 SMP Thu Mar 14 18:01:29 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.106-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-6.0.6-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-6.0.6-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-6.0.6-1.mga6.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-6.0.6-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-6.0.6-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.2.24-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi kernel-desktop-devel-latest
Package kernel-desktop-devel-latest-4.14.106-1.mga6.x86_64 is already installed
Marking kernel-desktop-devel-latest as manually installed, it won't be auto-orphaned
writing /var/lib/rpm/installed-through-deps.list
[root@localhost wilcal]# urpmi dkms-nvidia-current
Package dkms-nvidia-current-390.87-1.mga6.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.106-1.mga6.x86_64 is already installed
[root@localhost wilcal]# lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
Subsystem: Gigabyte Technology Co., Ltd Device 3518
Kernel driver in use: nvidia
Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current
Using: Mageia-7-beta2-Live-Xfce-i586.iso
Create a Vbox client. Works just fine. Boots to a working desktop.
install from update_testing:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
kernel-desktop-devel-latest dkms-nvidia-current cpupower
The following 10 packages are going to be installed:
- cpupower-4.14.116-1.mga6.x86_64
- kernel-desktop-4.14.116-1.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-4.14.116-1.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-latest-4.14.116-1.mga6.x86_64
- kernel-desktop-latest-4.14.116-1.mga6.x86_64
- meta-task-6-3.3.mga6.noarch
- vboxadditions-kernel-4.14.116-desktop-1.mga6-6.0.6-2.mga6.x86_64
- vboxadditions-kernel-desktop-latest-6.0.6-2.mga6.x86_64
- virtualbox-kernel-4.14.116-desktop-1.mga6-6.0.6-2.mga6.x86_64
- virtualbox-kernel-desktop-latest-6.0.6-2.mga6.x86_64
[root@localhost wilcal]# uname -a
Linux localhost 4.14.116-desktop-1.mga6 #1 SMP Sat May 4 08:34:09 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.116-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-6.0.6-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-6.0.6-2.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-6.0.6-1.mga6.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-6.0.6-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-6.0.6-2.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.2.24-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi kernel-desktop-devel-latest
Package kernel-desktop-devel-latest-4.14.116-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-nvidia-current
Package dkms-nvidia-current-390.87-1.mga6.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.116-1.mga6.x86_64 is already installed
[root@localhost wilcal]# lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
Subsystem: Gigabyte Technology Co., Ltd Device 3518
Kernel driver in use: nvidia
Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current
Mageia-7-beta2-Live-Xfce-i586.iso
Still works as a Vbox client. Boots to a working desktop.
Mageia-6.1-LiveDVD-GNOME-x86_64-DVD.iso
Create a Vbox client. Works just fine. Boots to a working desktop.
Mageia-Cauldron-netinstall-x86_64.iso
Installs as a Vbox client. Boots to a working desktop.
Updates then reboots back to a working desktop.
Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)
Intel Core i7-5700HQ (-HT-MCP-) NVIDIA GM204M [GeForce GTX 965M] *2 I$ uname -r 4.14.116-desktop-1.mga6 nstallation ran smoothly. tus tnvidia 410.78 Ran stress tests. Checked NFS shares and networking, LO writer, firefox, glmark2, image viewers. vlc, parole, mplayer - sound and video working. Laptop lid close and open resumes session. 64 bit OK on laptop Acer Aspire 7 A717-71G: Intel i5, Nvidia and Intel GPU:s but only intel is configured, as per default in Mageia installer. Disk: nVME SSD, EFI boot, separate /boot, then rest of system in LVM lv:s in a LUKS encrypted pv. Play video in firefox, other normal use... Suspend-resume incl wifi etc works. Mga6 on real 32bit hardware desktop(lxde/lxqt DE system)
$ uname -r
4.14.106-desktop-1.mga6
$ lscpu
Architecture: i686
CPU op-mode(s): 32-bit
AMD Athlon(tm) XP 2400+
Flags: fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge
mca cmov pat pse36 mmx fxsr sse syscall mmxext 3dnowext
3dnow cpuid 3dnowprefetch vmmcall
To satisfy dependencies, the following packages are going to be installed:
Package Version Release Arch
(medium "Core Updates Testing (distrib5)")
cpupower 4.14.116 1.mga6 i586
kernel-desktop-4.14.116-1.mga6 1 1.mga6 i586
kernel-desktop-latest 4.14.116 1.mga6 i586
kernel-userspace-headers 4.14.116 1.mga6 i586
wireguard-tools 0.0.20190406 1.mga6 i586
61MB of additional disk space will be used.
53MB of packages will be retrieved.
Proceed with the installation of the 5 packages? (Y/n) y
reboot -ok
$ uname -r
4.14.116-desktop-1.mga6
firefox -ok
usb detected and popup requesting action
vlc audio and video playback of .mkv file from usb - okCC:
(none) =>
westel
Advisory, added to svn:
type: security
subject: Updated kernel packages fixes security vulnerabilities
CVE:
- CVE-2019-3882
- CVE-2019-7308
- CVE-2019-11486
- CVE-2019-11599
src:
6:
core:
- kernel-4.14.116-1.mga6
- kernel-userspace-headers-4.14.116-1.mga6
- kmod-vboxadditions-6.0.6-2.mga6
- kmod-virtualbox-6.0.6-2.mga6
- kmod-xtables-addons-2.13-84.mga6
- wireguard-tools-0.0.20190406-1.mga6
description: |
This kernel update is based on the upstream 4.14.116 and fixes atleast
the following security issues:
A flaw was found in the Linux kernel's vfio interface implementation that
permits violation of the user's locked memory limit. If a device is bound
to a vfio driver, such as vfio-pci, and the local attacker is
administratively granted ownership of the device, it may cause a system
memory exhaustion and thus a denial of service (DoS) (CVE-2019-3882).
kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable
out-of-bounds speculation on pointer arithmetic in various cases, including
cases of different branches with different state or limits to sanitize,
leading to side-channel attacks (CVE-2019-7308).
The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the
Linux kernel before 5.0.8 has multiple race conditions (CVE-2019-11486).
The coredump implementation in the Linux kernel before 5.0.10 does not use
locking or other mechanisms to prevent vma layout or vma flags changes while
it runs, which allows local users to obtain sensitive information, cause a
denial of service, or possibly have unspecified other impact by triggering
a race condition with mmget_not_zero or get_task_mm calls (CVE-2019-11599).
WireGuard has been updated to 0.0.20190406.
For other uptstream fixes in this update, see the referenced changelogs.
references:
- https://bugs.mageia.org/show_bug.cgi?id=24773
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.107
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.108
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.109
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.110
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.111
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.112
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.113
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.114
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.115
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.116Keywords:
(none) =>
advisory Enough tests as this is also running on Mageia infra Whiteboard:
(none) =>
MGA6-32-OK MGA6-64-OK An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2019-0170.html Status:
NEW =>
RESOLVED |