Advisory: some CVEs fixed + other fixes ... will update it better soonish... SRPMS: kernel-3.10.58-1.mga3.src.rpm kernel-userspace-headers-3.10.58-1.mga3.src.rpm kmod-xtables-addons-2.3-24.mga3.src.rpm kmod-broadcom-wl-6.30.223.141-24.mga3.nonfree.src.rpm kmod-fglrx-13.251-14.mga3.nonfree.src.rpm kmod-nvidia173-173.14.38-38.mga3.nonfree.src.rpm kmod-nvidia304-304.108-24.mga3.nonfree.src.rpm kmod-nvidia-current-319.60-24.mga3.nonfree.src.rpm i586: cpupower-3.10.58-1.mga3.i586.rpm cpupower-devel-3.10.58-1.mga3.i586.rpm kernel-desktop-3.10.58-1.mga3-1-1.mga3.i586.rpm kernel-desktop586-3.10.58-1.mga3-1-1.mga3.i586.rpm kernel-desktop586-devel-3.10.58-1.mga3-1-1.mga3.i586.rpm kernel-desktop586-devel-latest-3.10.58-1.mga3.i586.rpm kernel-desktop586-latest-3.10.58-1.mga3.i586.rpm kernel-desktop-devel-3.10.58-1.mga3-1-1.mga3.i586.rpm kernel-desktop-devel-latest-3.10.58-1.mga3.i586.rpm kernel-desktop-latest-3.10.58-1.mga3.i586.rpm kernel-doc-3.10.58-1.mga3.noarch.rpm kernel-server-3.10.58-1.mga3-1-1.mga3.i586.rpm kernel-server-devel-3.10.58-1.mga3-1-1.mga3.i586.rpm kernel-server-devel-latest-3.10.58-1.mga3.i586.rpm kernel-server-latest-3.10.58-1.mga3.i586.rpm kernel-source-3.10.58-1.mga3-1-1.mga3.noarch.rpm kernel-source-latest-3.10.58-1.mga3.noarch.rpm kernel-userspace-headers-3.10.58-1.mga3.i586.rpm perf-3.10.58-1.mga3.i586.rpm xtables-addons-kernel-3.10.58-desktop-1.mga3-2.3-24.mga3.i586.rpm xtables-addons-kernel-3.10.58-desktop586-1.mga3-2.3-24.mga3.i586.rpm xtables-addons-kernel-3.10.58-server-1.mga3-2.3-24.mga3.i586.rpm xtables-addons-kernel-desktop586-latest-2.3-24.mga3.i586.rpm xtables-addons-kernel-desktop-latest-2.3-24.mga3.i586.rpm xtables-addons-kernel-server-latest-2.3-24.mga3.i586.rpm broadcom-wl-kernel-3.10.58-desktop-1.mga3-6.30.223.141-24.mga3.nonfree.i586.rpm broadcom-wl-kernel-3.10.58-desktop586-1.mga3-6.30.223.141-24.mga3.nonfree.i586.rpm broadcom-wl-kernel-3.10.58-server-1.mga3-6.30.223.141-24.mga3.nonfree.i586.rpm broadcom-wl-kernel-desktop586-latest-6.30.223.141-24.mga3.nonfree.i586.rpm broadcom-wl-kernel-desktop-latest-6.30.223.141-24.mga3.nonfree.i586.rpm broadcom-wl-kernel-server-latest-6.30.223.141-24.mga3.nonfree.i586.rpm fglrx-kernel-3.10.58-desktop-1.mga3-13.251-14.mga3.nonfree.i586.rpm fglrx-kernel-3.10.58-desktop586-1.mga3-13.251-14.mga3.nonfree.i586.rpm fglrx-kernel-3.10.58-server-1.mga3-13.251-14.mga3.nonfree.i586.rpm fglrx-kernel-desktop586-latest-13.251-14.mga3.nonfree.i586.rpm fglrx-kernel-desktop-latest-13.251-14.mga3.nonfree.i586.rpm fglrx-kernel-server-latest-13.251-14.mga3.nonfree.i586.rpm nvidia173-kernel-3.10.58-desktop-1.mga3-173.14.38-38.mga3.nonfree.i586.rpm nvidia173-kernel-3.10.58-desktop586-1.mga3-173.14.38-38.mga3.nonfree.i586.rpm nvidia173-kernel-3.10.58-server-1.mga3-173.14.38-38.mga3.nonfree.i586.rpm nvidia173-kernel-desktop586-latest-173.14.38-38.mga3.nonfree.i586.rpm nvidia173-kernel-desktop-latest-173.14.38-38.mga3.nonfree.i586.rpm nvidia173-kernel-server-latest-173.14.38-38.mga3.nonfree.i586.rpm nvidia304-kernel-3.10.58-desktop-1.mga3-304.108-24.mga3.nonfree.i586.rpm nvidia304-kernel-3.10.58-desktop586-1.mga3-304.108-24.mga3.nonfree.i586.rpm nvidia304-kernel-3.10.58-server-1.mga3-304.108-24.mga3.nonfree.i586.rpm nvidia304-kernel-desktop586-latest-304.108-24.mga3.nonfree.i586.rpm nvidia304-kernel-desktop-latest-304.108-24.mga3.nonfree.i586.rpm nvidia304-kernel-server-latest-304.108-24.mga3.nonfree.i586.rpm nvidia-current-kernel-3.10.58-desktop-1.mga3-319.60-24.mga3.nonfree.i586.rpm nvidia-current-kernel-3.10.58-desktop586-1.mga3-319.60-24.mga3.nonfree.i586.rpm nvidia-current-kernel-3.10.58-server-1.mga3-319.60-24.mga3.nonfree.i586.rpm nvidia-current-kernel-desktop586-latest-319.60-24.mga3.nonfree.i586.rpm nvidia-current-kernel-desktop-latest-319.60-24.mga3.nonfree.i586.rpm nvidia-current-kernel-server-latest-319.60-24.mga3.nonfree.i586.rpm x86_64: cpupower-3.10.58-1.mga3.x86_64.rpm cpupower-devel-3.10.58-1.mga3.x86_64.rpm kernel-desktop-3.10.58-1.mga3-1-1.mga3.x86_64.rpm kernel-desktop-devel-3.10.58-1.mga3-1-1.mga3.x86_64.rpm kernel-desktop-devel-latest-3.10.58-1.mga3.x86_64.rpm kernel-desktop-latest-3.10.58-1.mga3.x86_64.rpm kernel-doc-3.10.58-1.mga3.noarch.rpm kernel-server-3.10.58-1.mga3-1-1.mga3.x86_64.rpm kernel-server-devel-3.10.58-1.mga3-1-1.mga3.x86_64.rpm kernel-server-devel-latest-3.10.58-1.mga3.x86_64.rpm kernel-server-latest-3.10.58-1.mga3.x86_64.rpm kernel-source-3.10.58-1.mga3-1-1.mga3.noarch.rpm kernel-source-latest-3.10.58-1.mga3.noarch.rpm kernel-userspace-headers-3.10.58-1.mga3.x86_64.rpm perf-3.10.58-1.mga3.x86_64.rpm xtables-addons-kernel-3.10.58-desktop-1.mga3-2.3-24.mga3.x86_64.rpm xtables-addons-kernel-3.10.58-server-1.mga3-2.3-24.mga3.x86_64.rpm xtables-addons-kernel-desktop-latest-2.3-24.mga3.x86_64.rpm xtables-addons-kernel-server-latest-2.3-24.mga3.x86_64.rpm broadcom-wl-kernel-3.10.58-desktop-1.mga3-6.30.223.141-24.mga3.nonfree.x86_64.rpm broadcom-wl-kernel-3.10.58-server-1.mga3-6.30.223.141-24.mga3.nonfree.x86_64.rpm broadcom-wl-kernel-desktop-latest-6.30.223.141-24.mga3.nonfree.x86_64.rpm broadcom-wl-kernel-server-latest-6.30.223.141-24.mga3.nonfree.x86_64.rpm fglrx-kernel-3.10.58-desktop-1.mga3-13.251-14.mga3.nonfree.x86_64.rpm fglrx-kernel-3.10.58-server-1.mga3-13.251-14.mga3.nonfree.x86_64.rpm fglrx-kernel-desktop-latest-13.251-14.mga3.nonfree.x86_64.rpm fglrx-kernel-server-latest-13.251-14.mga3.nonfree.x86_64.rpm nvidia173-kernel-3.10.58-desktop-1.mga3-173.14.38-38.mga3.nonfree.x86_64.rpm nvidia173-kernel-3.10.58-server-1.mga3-173.14.38-38.mga3.nonfree.x86_64.rpm nvidia173-kernel-desktop-latest-173.14.38-38.mga3.nonfree.x86_64.rpm nvidia173-kernel-server-latest-173.14.38-38.mga3.nonfree.x86_64.rpm nvidia304-kernel-3.10.58-desktop-1.mga3-304.108-24.mga3.nonfree.x86_64.rpm nvidia304-kernel-3.10.58-server-1.mga3-304.108-24.mga3.nonfree.x86_64.rpm nvidia304-kernel-desktop-latest-304.108-24.mga3.nonfree.x86_64.rpm nvidia304-kernel-server-latest-304.108-24.mga3.nonfree.x86_64.rpm nvidia-current-kernel-3.10.58-desktop-1.mga3-319.60-24.mga3.nonfree.x86_64.rpm nvidia-current-kernel-3.10.58-server-1.mga3-319.60-24.mga3.nonfree.x86_64.rpm nvidia-current-kernel-desktop-latest-319.60-24.mga3.nonfree.x86_64.rpm nvidia-current-kernel-server-latest-319.60-24.mga3.nonfree.x86_64.rpm Reproducible: Steps to Reproduce:
Blocks: (none) => 14303
kernel-server i586 running fine on my Dell Optiplex 990 at work.
In VirtualBox, M4, KDE, 32-bit Package(s) under test: kernel-desktop-latest vboxadditions-kernel-desktop-latest default install of kernel-desktop-latest vboxadditions-kernel-desktop-latest [root@localhost wilcal]# uname -a Linux localhost 3.10.54-desktop-2.mga3 #1 SMP Sat Sep 13 14:46:46 UTC 2014 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-3.10.54-2.mga3.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-4.3.16-1.mga3.i586 is already installed System boots to a working desktop. Common apps work. install kernel-desktop-latest & vboxadditions-kernel-desktop-latest from updates_testing [root@localhost wilcal]# uname -a Linux localhost 3.10.58-desktop-1.mga3 #1 SMP Thu Oct 16 08:48:51 UTC 2014 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-3.10.58-1.mga3.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-4.3.18-2.mga3.i586 is already installed System boots to a working desktop. Common apps work. Test platform: Intel Core i7-2600K Sandy Bridge 3.4GHz GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB RTL8111/8168B PCI Express 1Gbit Ethernet DRAM 16GB (4 x 4GB) Mageia 4 64-bit, Nvidia driver virtualbox-4.3.10-1.1.mga4.x86_64 virtualbox-guest-additions-4.3.10-1.1.mga4.x86_64
CC: (none) => wilcal.int
(In reply to William Kenney from comment #2) Correction: > In VirtualBox, M4, KDE, 32-bit to In VirtualBox, M3, KDE, 32-bit
In VirtualBox, M3, KDE, 64-bit Package(s) under test: kernel-desktop-latest vboxadditions-kernel-desktop-latest default install of kernel-desktop-latest vboxadditions-kernel-desktop-latest [root@localhost wilcal]# uname -a Linux localhost 3.10.54-desktop-2.mga3 #1 SMP Sat Sep 13 14:20:45 UTC 2014 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-3.10.54-2.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-4.3.16-1.mga3.x86_64 is already installed System boots to a working desktop. Common apps work. install kernel-desktop-latest & vboxadditions-kernel-desktop-latest from updates_testing [root@localhost wilcal]# uname -a Linux localhost 3.10.58-desktop-1.mga3 #1 SMP Thu Oct 16 08:23:07 UTC 2014 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-3.10.58-1.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-4.3.18-2.mga3.x86_64 is already installed System boots to a working desktop. Common apps work. Test platform: Intel Core i7-2600K Sandy Bridge 3.4GHz GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB RTL8111/8168B PCI Express 1Gbit Ethernet DRAM 16GB (4 x 4GB) Mageia 4 64-bit, Nvidia driver virtualbox-4.3.10-1.1.mga4.x86_64 virtualbox-guest-additions-4.3.10-1.1.mga4.x86_64
On real hardware, M3, KDE, 32-bit Package(s) under test: kernel-desktop-latest virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo default install of: kernel-desktop-latest virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo [root@localhost wilcal]# uname -a Linux localhost 3.10.54-desktop-2.mga3 #1 SMP Sat Sep 13 14:46:46 UTC 2014 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-3.10.54-2.mga3.i586 is already installed [root@localhost wilcal]# urpmi virtualbox Package virtualbox-4.3.16-1.mga3.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-4.3.16-1.mga3.i586 is already installed [root@localhost wilcal]# urpmi dkms-virtualbox Package dkms-virtualbox-4.3.16-1.mga3.noarch is already installed [root@localhost wilcal]# urpmi virtualbox-guest-additions Package virtualbox-guest-additions-4.3.16-1.mga3.i586 is already installed [root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest Package virtualbox-kernel-desktop-latest-4.3.16-1.mga3.i586 is already installed [root@localhost wilcal]# urpmi x11-driver-video-vboxvideo Package x11-driver-video-vboxvideo-4.3.16-1.mga3.i586 is already installed [root@localhost wilcal]# lspci -k 00:02.0 VGA compatible controller: Intel Corporation 82915G/GV/910GL Integrated Graphics Controller (rev 04) Subsystem: Gigabyte Technology Co., Ltd GA-8I915ME-G Mainboard Kernel driver in use: i915 Kernel modules: i915, intelfb System boots to a working desktop. Common apps work. M4.1 KDE Live-CD runs as a Vbox client ( very slowly ). Screen sizes are correct. install: kernel-desktop-latest virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo from updates_testing [root@localhost wilcal]# uname -a Linux localhost 3.10.58-desktop-1.mga3 #1 SMP Thu Oct 16 08:48:51 UTC 2014 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-3.10.58-1.mga3.i586 is already installed [root@localhost wilcal]# urpmi virtualbox Package virtualbox-4.3.18-1.mga3.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-4.3.18-2.mga3.i586 is already installed [root@localhost wilcal]# urpmi dkms-virtualbox Package dkms-virtualbox-4.3.18-1.mga3.noarch is already installed [root@localhost wilcal]# urpmi virtualbox-guest-additions Package virtualbox-guest-additions-4.3.18-1.mga3.i586 is already installed [root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest Package virtualbox-kernel-desktop-latest-4.3.18-2.mga3.i586 is already installed [root@localhost wilcal]# urpmi x11-driver-video-vboxvideo Package x11-driver-video-vboxvideo-4.3.18-1.mga3.i586 is already installed [wilcal@localhost ~]$ lspci -k 00:02.0 VGA compatible controller: Intel Corporation 82915G/GV/910GL Integrated Graphics Controller (rev 04) Subsystem: Gigabyte Technology Co., Ltd GA-8I915ME-G Mainboard Kernel driver in use: i915 Kernel modules: i915, intelfb System boots to a working desktop. Common apps work. M4.1 KDE Live-CD runs as a Vbox client ( very slowly ). Screen sizes are correct. Test platform: Intel, P4 530J 3.0 GHz, 800MHz FSB, 1MB L2, LGA 775 GigaByte GA-81915G Pro F4 i915G LGA 775 MoBo Marvel Yukon 88E8001 Gigabit LAN Intel High Def Audio, Azalia (C-Media 9880) (snd-hda-intel) Intel Graphics Media Accelerator 900 (Intel 82915G) Kingston 4GB (2 x 2GB) DDR400 PC-3200 250GB Seagate Kingwin KF-91-BK SATA Mobile Rack Kingwin KF-91-T-BK SATA Mobile Rack Tray Sony CD/DVD-RW DWQ120AB2
On real hardware, M3, KDE, 64-bit Package(s) under test: kernel-desktop-latest virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo nvidia-current-kernel-desktop-latest default install of: kernel-desktop-latest virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo nvidia-current-kernel-desktop-latest [root@localhost wilcal]# uname -a Linux localhost 3.10.54-desktop-2.mga3 #1 SMP Sat Sep 13 14:20:45 UTC 2014 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-3.10.54-2.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox Package virtualbox-4.3.16-1.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-4.3.16-1.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi dkms-virtualbox Package dkms-virtualbox-4.3.16-1.mga3.noarch is already installed [root@localhost wilcal]# urpmi virtualbox-guest-additions Package virtualbox-guest-additions-4.3.16-1.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest Package virtualbox-kernel-desktop-latest-4.3.16-1.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi x11-driver-video-vboxvideo Package x11-driver-video-vboxvideo-4.3.16-1.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi nvidia-current-kernel-desktop-latest Package nvidia-current-kernel-desktop-latest-319.60-22.mga3.nonfree.x86_64 is already installed [root@localhost wilcal]# lspci -k 01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1) Subsystem: Gigabyte Technology Co., Ltd Device 3518 Kernel driver in use: nvidia Kernel modules: nvidiafb, nouveau, nvidia_current System boots to a working desktop. Common apps work. M4.1 KDE Live-CD runs as a Vbox client ( very slowly ). Screen sizes are correct. install: kernel-desktop-latest virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo nvidia-current-kernel-desktop-latest from updates_testing [root@localhost wilcal]# uname -a Linux localhost 3.10.58-desktop-1.mga3 #1 SMP Thu Oct 16 08:23:07 UTC 2014 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-3.10.58-1.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox Package virtualbox-4.3.18-1.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-4.3.18-2.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi dkms-virtualbox Package dkms-virtualbox-4.3.18-1.mga3.noarch is already installed [root@localhost wilcal]# urpmi virtualbox-guest-additions Package virtualbox-guest-additions-4.3.18-1.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest Package virtualbox-kernel-desktop-latest-4.3.18-2.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi x11-driver-video-vboxvideo Package x11-driver-video-vboxvideo-4.3.18-1.mga3.x86_64 is already installed [root@localhost wilcal]# urpmi nvidia-current-kernel-desktop-latest Package nvidia-current-kernel-desktop-latest-319.60-24.mga3.nonfree.x86_64 is already installed [wilcal@localhost ~]$ lspci -k 01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1) Subsystem: Gigabyte Technology Co., Ltd Device 3518 Kernel driver in use: nvidia Kernel modules: nvidiafb, nouveau, nvidia_current System boots to a working desktop. Common apps work. M4.1 KDE Live-CD runs as a Vbox client ( very slowly ). Screen sizes are correct. Test platform: Intel Core i7-2600K Sandy Bridge 3.4GHz GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB RTL8111/8168B PCI Express 1Gbit Ethernet DRAM 16GB (4 x 4GB) Mageia 4 64-bit, Nvidia driver virtualbox-4.3.10-1.1.mga4.x86_64 virtualbox-guest-additions-4.3.10-1.1.mga4.x86_64
That's not william real hardware testing it's still inside virtualbox,please real hardware testing means it's installed to hard drive not in virtualbox disk best how to do it is usb hard drive.
CC: (none) => ozkyster
Otto, please... Wilcal knows what he's doing... He tests both vbox installs and real hw, so he covers both...
Advisory: This kernel update is based on upstream -longterm 3.10.58 and fixes the following security issues: The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages (CVE-2014-3601). The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16.3 does not properly implement garbage collection, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via multiple "keyctl newring" operations followed by a "keyctl timeout" operation (CVE-2014-3631). The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both arguments to the pivot_root system call (CVE-2014-7970). The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call (CVE-2014-7975). For other fixes included in this update, read the referenced changelogs. References: https://bugs.mageia.org/show_bug.cgi?id=14302 https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.55 https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.56 https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.57 https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.58
I'm not sure if this will be rebuilt again (synthesis issue requiring new perl-URPM), but this can be validated. I'll leave this to Thomas.
Whiteboard: (none) => MGA3-32-OK MGA3-64-OK
I don't think the 3.10 branch is affected by the synthesis issue, the issue appeared with the 3.14 branch. We can probably check this by trying to update a pristine Mageia 3 release with updates_testing repos enabled. Or maybe downgrading perl-URPM to the core/release version would be enough.
CC: (none) => remi
Advisory uploaded.
Whiteboard: MGA3-32-OK MGA3-64-OK => MGA3-32-OK MGA3-64-OK advisory
I confirm that after reverting to perl-URPM-4.27-1.mga3 from Core Release, I was still able to install the kernel update from testing. Since Thomas is on the move, I guess we have to make the call for this one. WDYT David?
This one is good to go, but it'll go out with the virtualbox update, and therefore with the mga4 kernel update. Honestly, we could validate those too, and I was planning to this past weekend, but never found time to re-do my mga4 virtualbox testing. I guess it can wait a few more days.
Once the Mageia 4 kernel advisory is updated and uploaded, this update can be pushed. (Yes, I meant Mageia 4, as that kernel, this one, and virtualbox, have to be pushed together.)
Keywords: (none) => validated_updateCC: (none) => sysadmin-bugs
An update for this issue has been pushed to Mageia Updates repository. http://advisories.mageia.org/MGASA-2014-0454.html
Status: NEW => RESOLVEDResolution: (none) => FIXED