New kernels with more security fixes... Virtualbox packages in separate update report SRPMS: kernel-4.1.13-2.mga5.src.rpm kernel-userspace-headers-4.1.13-2.mga5.src.rpm kmod-xtables-addons-2.7-6.mga5.src.rpm kmod-broadcom-wl-6.30.223.271-3.mga5.nonfree.src.rpm kmod-fglrx-15.200.1046-7.mga5.nonfree.src.rpm kmod-nvidia304-304.128-3.mga5.nonfree.src.rpm kmod-nvidia340-340.93-3.mga5.nonfree.src.rpm kmod-nvidia-current-346.96-3.mga5.nonfree.src.rpm i586: cpupower-4.1.13-2.mga5.i586.rpm cpupower-devel-4.1.13-2.mga5.i586.rpm kernel-desktop-4.1.13-2.mga5-1-1.mga5.i586.rpm kernel-desktop586-4.1.13-2.mga5-1-1.mga5.i586.rpm kernel-desktop586-devel-4.1.13-2.mga5-1-1.mga5.i586.rpm kernel-desktop586-devel-latest-4.1.13-2.mga5.i586.rpm kernel-desktop586-latest-4.1.13-2.mga5.i586.rpm kernel-desktop-devel-4.1.13-2.mga5-1-1.mga5.i586.rpm kernel-desktop-devel-latest-4.1.13-2.mga5.i586.rpm kernel-desktop-latest-4.1.13-2.mga5.i586.rpm kernel-doc-4.1.13-2.mga5.noarch.rpm kernel-server-4.1.13-2.mga5-1-1.mga5.i586.rpm kernel-server-devel-4.1.13-2.mga5-1-1.mga5.i586.rpm kernel-server-devel-latest-4.1.13-2.mga5.i586.rpm kernel-server-latest-4.1.13-2.mga5.i586.rpm kernel-source-4.1.13-2.mga5-1-1.mga5.noarch.rpm kernel-source-latest-4.1.13-2.mga5.noarch.rpm kernel-userspace-headers-4.1.13-2.mga5.i586.rpm perf-4.1.13-2.mga5.i586.rpm xtables-addons-kernel-4.1.13-desktop-2.mga5-2.7-6.mga5.i586.rpm xtables-addons-kernel-4.1.13-desktop586-2.mga5-2.7-6.mga5.i586.rpm xtables-addons-kernel-4.1.13-server-2.mga5-2.7-6.mga5.i586.rpm xtables-addons-kernel-desktop586-latest-2.7-6.mga5.i586.rpm xtables-addons-kernel-desktop-latest-2.7-6.mga5.i586.rpm xtables-addons-kernel-server-latest-2.7-6.mga5.i586.rpm broadcom-wl-kernel-4.1.13-desktop-2.mga5-6.30.223.271-3.mga5.nonfree.i586.rpm broadcom-wl-kernel-4.1.13-desktop586-2.mga5-6.30.223.271-3.mga5.nonfree.i586.rpm broadcom-wl-kernel-4.1.13-server-2.mga5-6.30.223.271-3.mga5.nonfree.i586.rpm broadcom-wl-kernel-desktop586-latest-6.30.223.271-3.mga5.nonfree.i586.rpm broadcom-wl-kernel-desktop-latest-6.30.223.271-3.mga5.nonfree.i586.rpm broadcom-wl-kernel-server-latest-6.30.223.271-3.mga5.nonfree.i586.rpm fglrx-kernel-4.1.13-desktop-2.mga5-15.200.1046-7.mga5.nonfree.i586.rpm fglrx-kernel-4.1.13-desktop586-2.mga5-15.200.1046-7.mga5.nonfree.i586.rpm fglrx-kernel-4.1.13-server-2.mga5-15.200.1046-7.mga5.nonfree.i586.rpm fglrx-kernel-desktop586-latest-15.200.1046-7.mga5.nonfree.i586.rpm fglrx-kernel-desktop-latest-15.200.1046-7.mga5.nonfree.i586.rpm fglrx-kernel-server-latest-15.200.1046-7.mga5.nonfree.i586.rpm nvidia304-kernel-4.1.13-desktop-2.mga5-304.128-3.mga5.nonfree.i586.rpm nvidia304-kernel-4.1.13-desktop586-2.mga5-304.128-3.mga5.nonfree.i586.rpm nvidia304-kernel-4.1.13-server-2.mga5-304.128-3.mga5.nonfree.i586.rpm nvidia304-kernel-desktop586-latest-304.128-3.mga5.nonfree.i586.rpm nvidia304-kernel-desktop-latest-304.128-3.mga5.nonfree.i586.rpm nvidia304-kernel-server-latest-304.128-3.mga5.nonfree.i586.rpm nvidia340-kernel-4.1.13-desktop-2.mga5-340.93-3.mga5.nonfree.i586.rpm nvidia340-kernel-4.1.13-desktop586-2.mga5-340.93-3.mga5.nonfree.i586.rpm nvidia340-kernel-4.1.13-server-2.mga5-340.93-3.mga5.nonfree.i586.rpm nvidia340-kernel-desktop586-latest-340.93-3.mga5.nonfree.i586.rpm nvidia340-kernel-desktop-latest-340.93-3.mga5.nonfree.i586.rpm nvidia340-kernel-server-latest-340.93-3.mga5.nonfree.i586.rpm nvidia-current-kernel-4.1.13-desktop-2.mga5-346.96-3.mga5.nonfree.i586.rpm nvidia-current-kernel-4.1.13-desktop586-2.mga5-346.96-3.mga5.nonfree.i586.rpm nvidia-current-kernel-4.1.13-server-2.mga5-346.96-3.mga5.nonfree.i586.rpm nvidia-current-kernel-desktop586-latest-346.96-3.mga5.nonfree.i586.rpm nvidia-current-kernel-desktop-latest-346.96-3.mga5.nonfree.i586.rpm nvidia-current-kernel-server-latest-346.96-3.mga5.nonfree.i586.rpm x86_64: cpupower-4.1.13-2.mga5.x86_64.rpm cpupower-devel-4.1.13-2.mga5.x86_64.rpm kernel-desktop-4.1.13-2.mga5-1-1.mga5.x86_64.rpm kernel-desktop-devel-4.1.13-2.mga5-1-1.mga5.x86_64.rpm kernel-desktop-devel-latest-4.1.13-2.mga5.x86_64.rpm kernel-desktop-latest-4.1.13-2.mga5.x86_64.rpm kernel-doc-4.1.13-2.mga5.noarch.rpm kernel-server-4.1.13-2.mga5-1-1.mga5.x86_64.rpm kernel-server-devel-4.1.13-2.mga5-1-1.mga5.x86_64.rpm kernel-server-devel-latest-4.1.13-2.mga5.x86_64.rpm kernel-server-latest-4.1.13-2.mga5.x86_64.rpm kernel-source-4.1.13-2.mga5-1-1.mga5.noarch.rpm kernel-source-latest-4.1.13-2.mga5.noarch.rpm kernel-userspace-headers-4.1.13-2.mga5.x86_64.rpm perf-4.1.13-2.mga5.x86_64.rpm xtables-addons-kernel-4.1.13-desktop-2.mga5-2.7-6.mga5.x86_64.rpm xtables-addons-kernel-4.1.13-server-2.mga5-2.7-6.mga5.x86_64.rpm xtables-addons-kernel-desktop-latest-2.7-6.mga5.x86_64.rpm xtables-addons-kernel-server-latest-2.7-6.mga5.x86_64.rpm broadcom-wl-kernel-4.1.13-desktop-2.mga5-6.30.223.271-3.mga5.nonfree.x86_64.rpm broadcom-wl-kernel-4.1.13-server-2.mga5-6.30.223.271-3.mga5.nonfree.x86_64.rpm broadcom-wl-kernel-desktop-latest-6.30.223.271-3.mga5.nonfree.x86_64.rpm broadcom-wl-kernel-server-latest-6.30.223.271-3.mga5.nonfree.x86_64.rpm fglrx-kernel-4.1.13-desktop-2.mga5-15.200.1046-7.mga5.nonfree.x86_64.rpm fglrx-kernel-4.1.13-server-2.mga5-15.200.1046-7.mga5.nonfree.x86_64.rpm fglrx-kernel-desktop-latest-15.200.1046-7.mga5.nonfree.x86_64.rpm fglrx-kernel-server-latest-15.200.1046-7.mga5.nonfree.x86_64.rpm nvidia304-kernel-4.1.13-desktop-2.mga5-304.128-3.mga5.nonfree.x86_64.rpm nvidia304-kernel-4.1.13-server-2.mga5-304.128-3.mga5.nonfree.x86_64.rpm nvidia304-kernel-desktop-latest-304.128-3.mga5.nonfree.x86_64.rpm nvidia304-kernel-server-latest-304.128-3.mga5.nonfree.x86_64.rpm nvidia340-kernel-4.1.13-desktop-2.mga5-340.93-3.mga5.nonfree.x86_64.rpm nvidia340-kernel-4.1.13-server-2.mga5-340.93-3.mga5.nonfree.x86_64.rpm nvidia340-kernel-desktop-latest-340.93-3.mga5.nonfree.x86_64.rpm nvidia340-kernel-server-latest-340.93-3.mga5.nonfree.x86_64.rpm nvidia-current-kernel-4.1.13-desktop-2.mga5-346.96-3.mga5.nonfree.x86_64.rpm nvidia-current-kernel-4.1.13-server-2.mga5-346.96-3.mga5.nonfree.x86_64.rpm nvidia-current-kernel-desktop-latest-346.96-3.mga5.nonfree.x86_64.rpm nvidia-current-kernel-server-latest-346.96-3.mga5.nonfree.x86_64.rpm Reproducible: Steps to Reproduce:
Blocks: (none) => 17130
advisory (also added to svn) This kernel update is based on upstream 4.1.13 longterm kernel and fixes the following security issues: The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel before 4.2 attempts to support a FRAGLIST feature without proper memory allocation, which allows guest OS users to cause a denial of service (buffer overflow and memory corruption) via a crafted sequence of fragmented packets. (CVE-2015-5156) A guest to host DoS issue was found affecting various hypervisors. In that, a guest can DoS the host by triggering an infinite stream of "alignment check" (#AC) exceptions. This causes the microcode to enter an infinite loop where the core never receives another interrupt. The host kernel panics due to this effect (CVE-2015-5307). A guest to host DoS issue was found affecting various hypervisors. In that, a guest can DoS the host by triggering an infinite stream of "debug check" (#DB) exceptions. This causes the microcode to enter an infinite loop where the core never receives another interrupt. The host kernel panics due to this effect (CVE-2015-8104). For other fixes in this update, see the referenced changelog. references: - https://bugs.mageia.org/show_bug.cgi?id=17129 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.1.13
Whiteboard: (none) => advisory
Ok on both my i586 and x86_64 systems, both on real hardware and in virtualbox. Unless the security updates are considered critical, I'd like to wait a few days and have more people test it before adding the ok or validated tags.
CC: (none) => davidwhodgins
mga5 x86_64 Mate Installed desktop-latest packages on Gigabyte Sniper.Z97 system with GTX 770. Clean reboot. Running fine with nvidia driver 346.96. Leaving server and linus kernels until later.
CC: (none) => tarazed25
On real hardware, M5, KDE, 64-bit Package(s) under test: kernel-desktop-latest virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo nvidia-current-kernel-desktop-latest default install of: kernel-desktop-latest virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo nvidia-current-kernel-desktop-latest [root@localhost wilcal]# uname -a Linux localhost 4.1.12-desktop-1.mga5 #1 SMP Wed Oct 28 10:10:38 UTC 2015 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.1.12-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox Package virtualbox-5.0.8-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.0.8-2.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi dkms-virtualbox Package dkms-virtualbox-5.0.8-1.mga5.noarch is already installed [root@localhost wilcal]# urpmi virtualbox-guest-additions Package virtualbox-guest-additions-5.0.8-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest Package virtualbox-kernel-desktop-latest-5.0.8-2.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi x11-driver-video-vboxvideo Package x11-driver-video-vboxvideo-5.0.8-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi nvidia-current-kernel-desktop-latest Package nvidia-current-kernel-desktop-latest-346.96-2.mga5.nonfree.x86_64 is already installed [root@localhost wilcal]# lspci -k 01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1) Subsystem: Gigabyte Technology Co., Ltd Device 3518 Kernel driver in use: nvidia Kernel modules: nvidiafb, nouveau, nvidia_current System boots to a working desktop. Common apps work. M4.1 i586 KDE Live-CD runs as a Vbox client. M5 x86_64 Live-DVD installs, updates and runs as a Vbox client. Screen sizes of the host and client are correct. install: kernel-desktop-latest virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo nvidia-current-kernel-desktop-latest from updates_testing [root@localhost wilcal]# uname -a Linux localhost 4.1.13-desktop-2.mga5 #1 SMP Wed Nov 11 01:02:41 UTC 2015 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.1.13-2.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox Package virtualbox-5.0.10-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.0.10-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi dkms-virtualbox Package dkms-virtualbox-5.0.10-1.mga5.noarch is already installed [root@localhost wilcal]# urpmi virtualbox-guest-additions Package virtualbox-guest-additions-5.0.10-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest Package virtualbox-kernel-desktop-latest-5.0.10-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi x11-driver-video-vboxvideo Package x11-driver-video-vboxvideo-5.0.10-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi nvidia-current-kernel-desktop-latest Package nvidia-current-kernel-desktop-latest-346.96-3.mga5.nonfree.x86_64 is already installed [wilcal@localhost ~]$ lspci -k 01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1) Subsystem: Gigabyte Technology Co., Ltd Device 3518 Kernel driver in use: nvidia Kernel modules: nvidiafb, nouveau, nvidia_current System boots to a working desktop. Common apps work. Previously created M4.1 i586 KDE Live-CD runs as a Vbox client. Previously installed M5 x86_64 runs as a Vbox client. M5 x86-64 Gnome Live-DVD runs as a Vbox client. M5 i586 KDE Live-CD installs, updates and runs as a Vbox client. Screen sizes of the host and all clients are correct. Test platform: Intel Core i7-2600K Sandy Bridge 3.4GHz GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB RTL8111/8168B PCI Express 1Gbit Ethernet DRAM 16GB (4 x 4GB) Mageia 4 64-bit, Nvidia driver
CC: (none) => wilcal.int
mga5 x86_64 Mate This update is looking OK for Aorus X5 laptop Core i7-5700HQ 2.70GHz twin nvidia GTX 965M in SLI mode Intel Wireless 7265 wifi
Dell Dimension E310, P4 processor, Intel graphics, on both 64-bit and 32-bit Mageia installs. Installed desktop kernel at the same time as packages from Bug #17065 and Bug #17126. Only testing done was to install relevant packages from Mageia Update, reboot, and look for problems in general system operation. No issues noted in either installation. In fact, a minor scroll wheel problem in Mageia Update disappeared after the updates.
CC: (none) => andrewsfarm
Homemade computer, ASRock motherboard, Athlon X2 7750 processor, 8GB RAM, on-board ATI graphics. Installed updates on both 64-bit and 32-bit systems, as described in Comment 6. Did not install the virtualbox 5.0.10 packages until later. No issues to report. VirtualBox 5.0.8 packages updated as they should, and Windows XP guest worked.
(In reply to Thomas Andrews from comment #7) > Homemade computer, ASRock motherboard, Athlon X2 7750 processor, 8GB RAM, > on-board ATI graphics. > > Installed updates on both 64-bit and 32-bit systems, as described in Comment > 6. Did not install the virtualbox 5.0.10 packages until later. > > No issues to report. VirtualBox 5.0.8 packages updated as they should, and > Windows XP guest worked. Forgot to mention, each uses the server kernel.
Tested on workstations and servers at work, and my laptop, VirtualBox guest and host, VMWare guest, server and desktop kernel, Mageia 5 i586. No issues.
Whiteboard: advisory => MGA5-32-OK advisory
Whiteboard: MGA5-32-OK advisory => MGA5-32-OK MGA5-64-OK advisory
Testing on Athlon X2-3800 - Nvidia Drivers Installed: nvidia304-kernel-4.1.13-desktop586-2.mga5-304.128-3.mga5.nonfree.i586.rpm kernel-desktop-4.1.13-2.mga5-1-1.mga5.i586.rpm It picked up other packages as needed. System is functional. Linux localhost 4.1.13-desktop586-2.mga5 #1 SMP Wed Nov 11 00:50:24 UTC 2015 i686 i686 i686 GNU/Linux Brian
CC: (none) => brtians1
On x64 EFI real hardware with fglrx for AMD/ATI/Radeon video. I know this update has already been OK'd, but I should note that it is the first of many kernel updates (M4 included) which broke the booting. It now stops at a Grub prompt. No Mageia...
CC: (none) => lewyssmith
Thomas, please see comments from Lewis, thanks. Adding feedback marker.
Whiteboard: MGA5-32-OK MGA5-64-OK advisory => MGA5-32-OK MGA5-64-OK feedback advisory
(In reply to Lewis Smith from comment #11) > On x64 EFI real hardware with fglrx for AMD/ATI/Radeon video. > > I know this update has already been OK'd, but I should note that it is the > first of many kernel updates (M4 included) which broke the booting. It now > stops at a Grub prompt. No Mageia... I assume this is grub2-efi as its an efi system... Is kernel and initrd in /boot ? is the grub2 menu properly updated ?
(In reply to Thomas Backlund from comment #13) > I assume this is grub2-efi as its an efi system... Yes. > Is kernel and initrd in /boot ? Please tell me exactly what to look for. > is the grub2 menu properly updated ? I don't know. Again, tell me exactly what to look for. Thanks to Dave, I can chroot into the Mageia system. I re-built grub: # grub2-install --target=x86_64-efi --efi-directory=/boot/EFI --bootloader-id=mageia5 which finished rapidly, without the normal 10 minute wait that accompanies all kernel updates - including this one; attributed to os-prober. The result was still unbootable, stopping at the grub prompt. Interesting point: the current /boot/EFI/EFI/mageia/grubx64.efi is dated April, meaning that it has not been touched by subsequent kernel updates. So the problem seems to be elsewhere. I wondered whether the kernel stub got left out - if that matters. Please tell me all the booting steps I need to do that would be done as part of the kernel upgrade; exactly. And as a control, how I can UNinstall the kernel from the chrooted-to Mageia. Just urpme it? Which should re-generate the boot process without it.
When chrooted, ls -l /boot should show vmlinuz symlinked to the correct version for the kernel and similar for initrd.img linked to the correct .img file.
You don't actually need to chroot to do this bit btw, as long as the filesystem is mounted.
Thanks Claire. In /boot in the chroot'd Mageia: lrwxrwxrwx 1 root root 29 Tach 13 17:10 vmlinuz -> vmlinuz-4.1.13-desktop-2.mga5 lrwxrwxrwx 1 root root 29 Tach 13 17:10 vmlinuz-desktop -> vmlinuz-4.1.13-desktop-2.mga5 -rw-r--r-- 1 root root 4421616 Tach 11 02:05 vmlinuz-4.1.13-desktop-2.mga5 lrwxrwxrwx 1 root root 32 Tach 13 17:10 initrd.img -> initrd-4.1.13-desktop-2.mga5.img lrwxrwxrwx 1 root root 32 Tach 13 17:10 initrd-desktop.img -> initrd-4.1.13-desktop-2.mga5.img -rw------- 1 root root 11497381 Tach 13 17:00 initrd-4.1.13-desktop-2.mga5.img As for "is the grub2 menu properly updated ?", I await advice on knowing how. In the meantime, I am going to try urpme'ing the 4.1.13 kernel, which should leave 4.1.12 which worked OK previously. Just done that, took out while chroot'd: kernel-desktop-latest-4.1.13-2.mga5 kernel-desktop-devel-4.1.13-2.mga5-1-1.mga5 kernel-desktop-4.1.13-2.mga5-1-1.mga5 fglrx-kernel-4.1.13-desktop-2.mga5-15.200.1046-7.mga5.nonfree fglrx-kernel-desktop-latest-15.200.1046-7.mga5.nonfree.x86_64 -> -------- Uninstall Beginning -------- Module: fglrx Version: 15.200.1046-1.1.mga5.nonfree Kernel: 4.1.13-desktop-2.mga5 (x86_64) ------------------------------------- Status: Before uninstall, this module version was ACTIVE on this kernel. fglrx.ko.xz: - Uninstallation - Deleting from: /lib/modules/4.1.13-desktop-2.mga5/dkms-binary/drivers/char/drm/ - Original module - No original module was found for this module on this kernel. - Use the dkms install command to reinstall any previous module version. depmod......... DKMS: uninstall Completed. - fglrx-kernel-4.1.13-desktop-2.mga5-15.200.1046-7.mga5.nonfree.x86_64 -> Cannot find a boot loader installed. Only taking care of initrd - kernel-desktop-4.1.13-2.mga5-1-1.mga5.x86_64 No boot re-build, I think. I am not putting any money on the thing booting OK.
Lewis, please file a bug for the issue you saw. This isn't a bug with the kernel package, but with bootloader-utils. That's where the scripts come from that the kernel runs when it's installed to get it added to the bootloader configuration. Sometimes, these scripts do bad things (see Bug 17000 for another example), but we don't know why, since it's only sometimes. It would be good to know if Lewis can reproduce this issue, and if someone else can replicate his setup and reproduce it as well.
As discussed on irc, validating
Keywords: (none) => validated_updateWhiteboard: MGA5-32-OK MGA5-64-OK feedback advisory => MGA5-32-OK MGA5-64-OK advisoryCC: (none) => sysadmin-bugs
An update for this issue has been pushed to Mageia Updates repository. http://advisories.mageia.org/MGASA-2015-0450.html
Status: NEW => RESOLVEDResolution: (none) => FIXED