Advisory: This update is based on upstream 4.4.32 and fixes alteast the following security issues: The proc_keys_show function in security/keys/proc.c in the Linux kernel through 4.8.2, when the GNU Compiler Collection (gcc) stack protector is enabled, uses an incorrect buffer size for certain timeout data, which allows local users to cause a denial of service (stack memory corruption and panic) by reading the /proc/keys file (CVE-2016-7042). Null pointer dereference in kvm/emulate.c (CVE-2016-8630). A buffer overflow vulnerability due to a lack of input filtering of incoming fragmented datagrams was found in the IP-over-1394 driver [firewire-net] in a fragment handling code in the Linux kernel. A maliciously formed fragment with a respectively large datagram offset would cause a memcpy() past the datagram buffer, which would cause a system panic or possible arbitrary code execution. The flaw requires [firewire-net] module to be loaded and is remotely exploitable from connected firewire devices, but not over a local network (CVE-2016-8633). For other fixes in this update, see the referenced changelogs. References: https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.31 https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.32 SRPMS: kernel-4.4.32-1.mga5.src.rpm kernel-userspace-headers-4.4.32-1.mga5.src.rpm kmod-vboxadditions-5.1.2-11.mga5.src.rpm kmod-virtualbox-5.1.2-11.mga5.src.rpm kmod-xtables-addons-2.10-16.mga5.src.rpm i586: cpupower-4.4.32-1.mga5.i586.rpm cpupower-devel-4.4.32-1.mga5.i586.rpm kernel-desktop-4.4.32-1.mga5-1-1.mga5.i586.rpm kernel-desktop586-4.4.32-1.mga5-1-1.mga5.i586.rpm kernel-desktop586-devel-4.4.32-1.mga5-1-1.mga5.i586.rpm kernel-desktop586-devel-latest-4.4.32-1.mga5.i586.rpm kernel-desktop586-latest-4.4.32-1.mga5.i586.rpm kernel-desktop-devel-4.4.32-1.mga5-1-1.mga5.i586.rpm kernel-desktop-devel-latest-4.4.32-1.mga5.i586.rpm kernel-desktop-latest-4.4.32-1.mga5.i586.rpm kernel-doc-4.4.32-1.mga5.noarch.rpm kernel-server-4.4.32-1.mga5-1-1.mga5.i586.rpm kernel-server-devel-4.4.32-1.mga5-1-1.mga5.i586.rpm kernel-server-devel-latest-4.4.32-1.mga5.i586.rpm kernel-server-latest-4.4.32-1.mga5.i586.rpm kernel-source-4.4.32-1.mga5-1-1.mga5.noarch.rpm kernel-source-latest-4.4.32-1.mga5.noarch.rpm kernel-userspace-headers-4.4.32-1.mga5.i586.rpm perf-4.4.32-1.mga5.i586.rpm vboxadditions-kernel-4.4.32-desktop-1.mga5-5.1.2-11.mga5.i586.rpm vboxadditions-kernel-4.4.32-desktop586-1.mga5-5.1.2-11.mga5.i586.rpm vboxadditions-kernel-4.4.32-server-1.mga5-5.1.2-11.mga5.i586.rpm vboxadditions-kernel-desktop586-latest-5.1.2-11.mga5.i586.rpm vboxadditions-kernel-desktop-latest-5.1.2-11.mga5.i586.rpm vboxadditions-kernel-server-latest-5.1.2-11.mga5.i586.rpm virtualbox-kernel-4.4.32-desktop-1.mga5-5.1.2-11.mga5.i586.rpm virtualbox-kernel-4.4.32-desktop586-1.mga5-5.1.2-11.mga5.i586.rpm virtualbox-kernel-4.4.32-server-1.mga5-5.1.2-11.mga5.i586.rpm virtualbox-kernel-desktop586-latest-5.1.2-11.mga5.i586.rpm virtualbox-kernel-desktop-latest-5.1.2-11.mga5.i586.rpm virtualbox-kernel-server-latest-5.1.2-11.mga5.i586.rpm xtables-addons-kernel-4.4.32-desktop-1.mga5-2.10-16.mga5.i586.rpm xtables-addons-kernel-4.4.32-desktop586-1.mga5-2.10-16.mga5.i586.rpm xtables-addons-kernel-4.4.32-server-1.mga5-2.10-16.mga5.i586.rpm xtables-addons-kernel-desktop586-latest-2.10-16.mga5.i586.rpm xtables-addons-kernel-desktop-latest-2.10-16.mga5.i586.rpm xtables-addons-kernel-server-latest-2.10-16.mga5.i586.rpm x86_64: cpupower-4.4.32-1.mga5.x86_64.rpm cpupower-devel-4.4.32-1.mga5.x86_64.rpm kernel-desktop-4.4.32-1.mga5-1-1.mga5.x86_64.rpm kernel-desktop-devel-4.4.32-1.mga5-1-1.mga5.x86_64.rpm kernel-desktop-devel-latest-4.4.32-1.mga5.x86_64.rpm kernel-desktop-latest-4.4.32-1.mga5.x86_64.rpm kernel-doc-4.4.32-1.mga5.noarch.rpm kernel-server-4.4.32-1.mga5-1-1.mga5.x86_64.rpm kernel-server-devel-4.4.32-1.mga5-1-1.mga5.x86_64.rpm kernel-server-devel-latest-4.4.32-1.mga5.x86_64.rpm kernel-server-latest-4.4.32-1.mga5.x86_64.rpm kernel-source-4.4.32-1.mga5-1-1.mga5.noarch.rpm kernel-source-latest-4.4.32-1.mga5.noarch.rpm kernel-userspace-headers-4.4.32-1.mga5.x86_64.rpm perf-4.4.32-1.mga5.x86_64.rpm vboxadditions-kernel-4.4.32-desktop-1.mga5-5.1.2-11.mga5.x86_64.rpm vboxadditions-kernel-4.4.32-server-1.mga5-5.1.2-11.mga5.x86_64.rpm vboxadditions-kernel-desktop-latest-5.1.2-11.mga5.x86_64.rpm vboxadditions-kernel-server-latest-5.1.2-11.mga5.x86_64.rpm virtualbox-kernel-4.4.32-desktop-1.mga5-5.1.2-11.mga5.x86_64.rpm virtualbox-kernel-4.4.32-server-1.mga5-5.1.2-11.mga5.x86_64.rpm virtualbox-kernel-desktop-latest-5.1.2-11.mga5.x86_64.rpm virtualbox-kernel-server-latest-5.1.2-11.mga5.x86_64.rpm xtables-addons-kernel-4.4.32-desktop-1.mga5-2.10-16.mga5.x86_64.rpm xtables-addons-kernel-4.4.32-server-1.mga5-2.10-16.mga5.x86_64.rpm xtables-addons-kernel-desktop-latest-2.10-16.mga5.x86_64.rpm xtables-addons-kernel-server-latest-2.10-16.mga5.x86_64.rpm
CC: (none) => andrewsfarm
Installed on x86_64 hardware with nvidia GTX970. Rebooted fine. Building a virtualbox later.
CC: (none) => tarazed25
On real x86_64 hardware, HP Probook 6550b, i3, 4GB, Intel graphics, Intel wifi. This computer already had been updated to VirtualBox 5.1.8 during testing, so the 4.4.32 kernel modules were built locally during installation. No regressions noted. All apps seem to work, including VirtualBox 5.1.8. Also, in both i586 and x86_64 Mageia 5 guests, built several months ago, with guest addition kmods built locally during update: No regressions noted. All apps seem to work.
On real hardware, Athlon X2 7750, 8GB, Nvidia graphics using the 340 driver: 5.1 i586 install created two days ago using the Nov 7 Classical iso, and fully updated afterward, including an install of VirtualBox 5.1.2, with a Mageia 5 guest created from the same iso. No problems noted, except for a small glitch with VirtualBox. Before the kernel update, the Mageia 5 guest would start OK. Afterward, it wouldn't start until I disabled hardware acceleration for the guest. I believe this is not a regression, but rather a case of insufficient hardware while in 32-bit mode. In the 32-bit guest, no regressions noted after the update. Operation seemed slow with hardware acceleration off, but that's to be expected.
Forgot to mention, the Probook uses the 64-bit desktop kernel, while the AMD hardware uses the 32-bit server kernel. All guests are using the desktop kernels.
Installed the following packages on a 64 bits Mageia 5 installation in a MSI Cubi PC. - cpupower-4.4.32-1.mga5.x86_64 - kernel-desktop-4.4.32-1.mga5-1-1.mga5.x86_64 - kernel-desktop-latest-4.4.32-1.mga5.x86_64 - kernel-userspace-headers-4.4.32-1.mga5.x86_64 Everything seems to work fine.
CC: (none) => panasum
CC: (none) => davidwhodginsWhiteboard: (none) => advisory
On same hardware as Comment #3, 64-bit install, server kernel, VirtualBox 5.1.8 already installed. Updated kernel, with nvidia 340 and vbox 5.1.8 kernel mods built locally. All seems well. No regressions noted. Also, on the same machine, two Mageia 5 guests updated, one 32-bit the other 64-bit. Recent updates applied first, before those under test, and machine rebooted. Guest additions module for vbox 5.1.8 built locally. All seems well. No regressions noted. Still using nomodeset option for guests, and I didn't try booting without that option.
On real hardware, M5, KDE, 64-bit initial install: kernel-desktop-latest virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo kernel-desktop-devel-latest nvidia-current-kernel-desktop-latest [root@localhost wilcal]# uname -a Linux localhost 4.4.30-desktop-2.mga5 #1 SMP Fri Nov 4 19:17:03 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.4.30-2.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox Package virtualbox-5.1.2-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.2-10.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi dkms-virtualbox Package dkms-virtualbox-5.1.2-1.mga5.noarch is already installed [root@localhost wilcal]# urpmi virtualbox-guest-additions Package virtualbox-guest-additions-5.1.2-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest Package virtualbox-kernel-desktop-latest-5.1.2-10.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi x11-driver-video-vboxvideo Package x11-driver-video-vboxvideo-5.1.2-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi kernel-desktop-devel-latest Package kernel-desktop-devel-latest-4.4.30-2.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi nvidia-current-kernel-desktop-latest Package nvidia-current-kernel-desktop-latest-352.79-10.mga5.nonfree.x86_64 is already installed [wilcal@localhost ~]$ lspci -k 01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1) Subsystem: Gigabyte Technology Co., Ltd Device 3518 Kernel driver in use: nvidia Kernel modules: nvidiafb, nouveau, nvidia_current M5 i586 Gnome Live-CD runs as a Vbox client. Boots to a working desktop. Common apps work. Screen sizes are correct. install or check: kernel-desktop-latest virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo kernel-desktop-devel-latest nvidia-current-kernel-desktop-latest from updates_testing [root@localhost wilcal]# uname -a Linux localhost 4.4.32-desktop-1.mga5 #1 SMP Tue Nov 15 09:08:15 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.4.32-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox Package virtualbox-5.1.2-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.2-11.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi dkms-virtualbox Package dkms-virtualbox-5.1.2-1.mga5.noarch is already installed [root@localhost wilcal]# urpmi virtualbox-guest-additions Package virtualbox-guest-additions-5.1.2-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest Package virtualbox-kernel-desktop-latest-5.1.2-11.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi x11-driver-video-vboxvideo Package x11-driver-video-vboxvideo-5.1.2-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi kernel-desktop-devel-latest Package kernel-desktop-devel-latest-4.4.32-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi nvidia-current-kernel-desktop-latest Package nvidia-current-kernel-desktop-latest-352.79-10.mga5.nonfree.x86_64 is already installed [wilcal@localhost ~]$ lspci -k 01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1) Subsystem: Gigabyte Technology Co., Ltd Device 3518 Kernel driver in use: nvidia Kernel modules: nvidiafb, nouveau, nvidia_current System boots to a working desktop. Common apps work. Previously created M5 i586 Gnome Live-CD runs as a Vbox client. M5 Gnome x86_64 Live-DVD runs as a Vbox client. M5 x86_64 KDE Live-DVD runs, installs and updates as a Vbox client. Test platform: Intel Core i7-2600K Sandy Bridge 3.4GHz GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB RTL8111/8168B PCI Express 1Gbit Ethernet DRAM 16GB (4 x 4GB) looks good
CC: (none) => wilcal.int
MGA5-32 on Acer D620 Xfce No installation issues No apparant problems after reboot. I don't do Vbox on this machine as really short of power.
CC: (none) => herman.viaene
On mga5-32 Packages installed: - cpupower-4.4.32-1.mga5.i586 - kernel-desktop-4.4.32-1.mga5-1-1.mga5.i586 - kernel-desktop-latest-4.4.32-1.mga5.i586 Packages installed cleanly System re-booted normally No regressions noted OK for mga5-32 on this system: Machine: Mobo: ECS model: GeForce7050M-M v: CPU: Quad core AMD Phenom 9500 (-MCP-) raphics: Card: NVIDIA GF108 [GeForce GT 630] Display Server: X.Org 1.16.4 drivers: v4l,nouveau
CC: (none) => jim
On mga5-64 Pakages installed: - cpupower-4.4.32-1.mga5.x86_64 - kernel-desktop-4.4.32-1.mga5-1-1.mga5.x86_64 - kernel-desktop-latest-4.4.32-1.mga5.x86_64 Packages installed cleanly System re-booted normally No regressions noted OK for mga5-64 on this system: mobo: ECS model: GeForce7050M-M v: 1.0 CPU: Quad core AMD Phenom 9500 (-MCP-) Graphics: Card: NVIDIA GF108 [GeForce GT 630] Display Server: X.Org 1.16.4 drivers: v4l,nouveau Boot: legacy BIOS; Grub2 Disk: GPT partitions
On real hardware: Sempron 3100+ processor, 2GB RAM, Nvidia graphics using 304 driver, BCM4318 wifi. Updated 32-bit server kernel. I did not attempt to change the wifi from using proprietary firmware to opensource firmware, as I am not the primary user of this system and I didn't want to take the chance of breaking wifi at this time. All looks good. Nvidia module built locally (I had forgotten just how long this takes on this older, slower machine. I began to wonder if things were "stuck" after a while.) Wifi still works, as does other common software.
In VirtualBox, M5, KDE, 32-bit boot with "nomodeset" kernel option Package(s) under test: kernel-desktop-latest vboxadditions-kernel-desktop-latest kernel-desktop-devel-latest default install of: kernel-desktop-latest vboxadditions-kernel-desktop-latest kernel-desktop-devel-latest [root@localhost wilcal]# uname -a Linux localhost.localdomain 4.4.30-desktop586-2.mga5 #1 SMP Fri Nov 4 19:15:46 UTC 2016 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.4.30-2.mga5.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.2-10.mga5.i586 is already installed [root@localhost wilcal]# urpmi kernel-desktop-devel-latest Package kernel-desktop-devel-latest-4.4.30-2.mga5.i586 is already installed System boots to a working desktop. Common apps work. Screen dimensions are correct. install: kernel-desktop-latest vboxadditions-kernel-desktop-latest kernel-desktop-devel-latest from updates_testing [root@localhost wilcal]# uname -a Linux localhost.localdomain 4.4.30-desktop586-2.mga5 #1 SMP Fri Nov 4 19:15:46 UTC 2016 i686 i686 i686 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.4.32-1.mga5.i586 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.2-11.mga5.i586 is already installed [root@localhost wilcal]# urpmi kernel-desktop-devel-latest Package kernel-desktop-devel-latest-4.4.32-1.mga5.i586 is already installed System boots to a working desktop. Common apps work. Screen dimensions are correct.
In VirtualBox, M5, KDE, 64-bit boot with "nomodeset" kernel option Package(s) under test: kernel-desktop-latest vboxadditions-kernel-desktop-latest kernel-desktop-devel-latest default install of: kernel-desktop-latest vboxadditions-kernel-desktop-latest kernel-desktop-devel-latest [root@localhost wilcal]# uname -a Linux localhost.localdomain 4.4.30-desktop-2.mga5 #1 SMP Fri Nov 4 19:17:03 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.4.30-2.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.2-10.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi kernel-desktop-devel-latest Package kernel-desktop-devel-latest-4.4.30-2.mga5.x86_64 is already installed System boots to a working desktop. Common apps work. Screen dimensions are correct. install: kernel-desktop-latest vboxadditions-kernel-desktop-latest kernel-desktop-devel-latest from updates_testing [root@localhost wilcal]# uname -a Linux localhost.localdomain 4.4.32-desktop-1.mga5 #1 SMP Tue Nov 15 09:08:15 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.4.32-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.2-11.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi kernel-desktop-devel-latest Package kernel-desktop-devel-latest-4.4.32-1.mga5.x86_64 is already installed System boots to a working desktop. Common apps work. Screen dimensions are correct.
Updated a real hardware install created from the last round of 5.1 LiveDVD isos. Hardware is a Dell Dimension E310, P4, Intel graphics, BCM4318 wifi. During the install, I discovered that the LiveDVD had installed the vbox guest addition kernel modules, when it shouldn't have. I removed them before the update. MCC is also indicating a number of orphan packages, including several x11 drivers. I have NOT removed those "orphans," as I question the validity. I went ahead and did the kernel update. Everything seems fine, except as noted above. Wifi continues to work. So do other apps. Since new 5.1 LiveDVDs are due out in a few hours, I will be re-doing this install to see if the above-mentioned problems still exist. But as far as I can tell, this kernel is OK on this hardware.
Did a "clean" re-install from the Nov 20 64-bit Classical 5.1 iso on my Probook 6550b, for reasons unrelated to any particular updates. In the process, I rolled back vbox to version 5.1.2. When all dust had settled, I updated to this kernel, including the vbox modules. All seems well this time, too. No regressions noted.
Physical Hardware - Core I3 Laptop Processor Intel Video, 2 GB of RAM - i586 5.1 version of Mageia is on machine $ uname -a Linux localhost.localdomain 4.4.32-desktop586-1.mga5 #1 SMP Tue Nov 15 09:07:49 UTC 2016 i686 i686 i686 GNU/Linux Installed kernel update and CPUPower. All seems to be working as designed.
CC: (none) => brtians1
Meant to complete my testing last weekend but finally just did, working fine for me (and others) on multiple Mageia 5 i586 and x86_64 systems. We can validate this.
Whiteboard: advisory => MGA5-32-OK MGA5-64-OK advisory
Validating. Advisory already in place.
Keywords: (none) => validated_updateCC: (none) => lewyssmith, sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. http://advisories.mageia.org/MGASA-2016-0401.html
Status: NEW => RESOLVEDResolution: (none) => FIXED