Bug 19994 - Update request: nvidia-current-375.26-1.mga5.nonfree
Summary: Update request: nvidia-current-375.26-1.mga5.nonfree
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA5-64-OK MGA5-32-OK advisory
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2016-12-19 21:56 CET by Thomas Backlund
Modified: 2017-01-28 09:00 CET (History)
6 users (show)

See Also:
Source RPM: nvidia-current
CVE:
Status comment:


Attachments

Description Thomas Backlund 2016-12-19 21:56:39 CET
Security fixes and update to new long lived branch to support nvidia gtx 10xx series hw, advisory to follow:

Theese packages are already in use in mga6/cauldron



SRPMS:
ldetect-lst-0.1.346.5-1.mga5.src.rpm

nvidia-current-375.26-1.mga5.nonfree.src.rpm



i586:
ldetect-lst-0.1.346.5-1.mga5.i586.rpm
ldetect-lst-devel-0.1.346.5-1.mga5.i586.rpm

dkms-nvidia-current-375.26-1.mga5.nonfree.i586.rpm
nvidia-current-cuda-opencl-375.26-1.mga5.nonfree.i586.rpm
nvidia-current-devel-375.26-1.mga5.nonfree.i586.rpm
nvidia-current-doc-html-375.26-1.mga5.nonfree.i586.rpm
x11-driver-video-nvidia-current-375.26-1.mga5.nonfree.i586.rpm



x86_64:
ldetect-lst-0.1.346.5-1.mga5.x86_64.rpm
ldetect-lst-devel-0.1.346.5-1.mga5.x86_64.rpm

dkms-nvidia-current-375.26-1.mga5.nonfree.x86_64.rpm
nvidia-current-cuda-opencl-375.26-1.mga5.nonfree.x86_64.rpm
nvidia-current-devel-375.26-1.mga5.nonfree.x86_64.rpm
nvidia-current-doc-html-375.26-1.mga5.nonfree.x86_64.rpm
x11-driver-video-nvidia-current-375.26-1.mga5.nonfree.x86_64.rpm
Comment 1 Thomas Backlund 2016-12-22 20:00:13 CET
Advisory:
This proprietary nvidia-current driver update provides an upgrade to the
new R375 long lived branch adding support for nVidia Geforce 10 (GTX10xx,
Pascal) series hardware and fixes the following security issues:

NVIDIA GPU Display Driver contains a vulnerability in the kernel mode
layer (nvidia.ko) handler where a missing permissions check may allow
users to gain access to arbitrary physical memory, leading to an
escalation of privileges (CVE-2016-7382).

NVIDIA GPU Display Driver on Linux contains a vulnerability in the kernel
mode layer (nvidia.ko) handler for mmap() where improper input validation
may allow users to gain access to arbitrary physical memory, leading to
an escalation of privileges (CVE-2016-7389).


NVIDIA GPU Display Driver contains a vulnerability in the kernel mode
layer (nvidia.ko) where a user can cause a GPU interrupt storm, leading
to a denial of service (CVE-2016-8826).

References:
http://nvidia.custhelp.com/app/answers/detail/a_id/4246
http://nvidia.custhelp.com/app/answers/detail/a_id/4278
Comment 2 Len Lawrence 2016-12-29 18:58:39 CET
This is working fine on x86_64 hardware with GeForce GTX 770.
Kernel 4.4.39-tmb-desktop-1.mga5

Running OK on another machine with GeForce GTX 970.
Kernel 4.4.36-desktop-2.mga5

CC: (none) => tarazed25

Comment 3 William Kenney 2017-01-20 00:37:28 CET
On real hardware, M5, KDE, 64-bit

Package(s) under test:
dkms-nvidia-current
nvidia-current-doc-html
x11-driver-video-nvidia-current

default install of nvidia-current-kernel-desktop-latest dkms-nvidia-current
x11-driver-video-nvidia-current urpmi ldetect-lst virtualbox x11-driver-video-vboxvideo

[root@localhost wilcal]# uname -a
Linux localhost 4.4.39-desktop-1.mga5 #1 SMP Fri Dec 16 18:43:46 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi nvidia-current-kernel-desktop-latest
Package nvidia-current-kernel-desktop-latest-352.79-10.mga5.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-nvidia-current
Package dkms-nvidia-current-352.79-3.mga5.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-nvidia-current
Package x11-driver-video-nvidia-current-352.79-3.mga5.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi ldetect-lst
Package ldetect-lst-0.1.346.4-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-5.1.10-1.1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.1.10-1.1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-5.1.10-3.1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.4.39-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi nvidia-current-doc-html
Package nvidia-current-doc-html-352.79-3.mga5.nonfree.x86_64 is already installed
[wilcal@localhost ~]$ lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
        Subsystem: Gigabyte Technology Co., Ltd Device 3518
        Kernel driver in use: nvidia
        Kernel modules: nvidiafb, nouveau, nvidia_current

Boots to a working desktop. Screen sizes are correct. Vbox runs M5 x86_64 Gnome Live-DVD as a client.
Vbox runs M5 x86_64 KDE Live-DVD as a client. All screen sizes are correct.

install dkms-nvidia-current nvidia-current-doc-html x11-driver-video-nvidia-current from updates_testing

reboot system

[root@localhost wilcal]# uname -a
Linux localhost 4.4.39-desktop-1.mga5 #1 SMP Fri Dec 16 18:43:46 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi nvidia-current-kernel-desktop-latest
Package nvidia-current-kernel-desktop-latest-352.79-10.mga5.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-nvidia-current
Package dkms-nvidia-current-375.26-1.mga5.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-nvidia-current
Package x11-driver-video-nvidia-current-375.26-1.mga5.nonfree.x86_64 is already installed
[root@localhost wilcal]# urpmi ldetect-lst
Package ldetect-lst-0.1.346.5-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-5.1.10-1.1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.1.10-1.1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-5.1.10-3.1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.4.39-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi nvidia-current-doc-html
Package nvidia-current-doc-html-375.26-1.mga5.nonfree.x86_64 is already installed
[wilcal@localhost ~]$ lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
        Subsystem: Gigabyte Technology Co., Ltd Device 3518
        Kernel driver in use: nvidia
        Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current

Boots to a working desktop. Screen sizes are correct. Vbox runs M5 x86_64 Gnome Live-DVD as a client.
Vbox runs M5 x86_64 KDE Live-DVD as a client. All screen sizes are correct.

Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)
Mageia 5 64-bit, nvidia driver
virtualbox-5.1.10-1.mga4.x86_64
virtualbox-guest-additions-5.1.10-1.mga4.x86_64

CC: (none) => wilcal.int

Len Lawrence 2017-01-27 08:46:22 CET

Whiteboard: (none) => MGA5-64-OK

Comment 4 Lewis Smith 2017-01-27 11:36:58 CET
Advisory taken from comments 0 & 1.

Whiteboard: MGA5-64-OK => MGA5-64-OK advisory
CC: (none) => lewyssmith

Comment 5 Herman Viaene 2017-01-27 14:12:21 CET
MGA5-32 on AsusA6000VM Xfce
No installation issues.
Rebooted after installation and checked that nvidia is used in Xorg.conf, working desktop OK.

Whiteboard: MGA5-64-OK advisory => MGA5-64-OK MGA5-32-OK advisory
CC: (none) => herman.viaene

Comment 6 Lewis Smith 2017-01-27 15:00:15 CET
Thanks to testers of this update. Validating.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 7 Mageia Robot 2017-01-27 21:31:43 CET
An update for this issue has been pushed to the Mageia Updates repository.

http://advisories.mageia.org/MGASA-2017-0025.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 8 Didier Le Gloanic 2017-01-28 09:00:17 CET
That update result in a lack of graphical interface on my computer.
The booting list of services note nvidia OK but then hang when it should go graphic.
When downgrading to previous version, at the end urpmi notify that version 375.26
was inactive for that kernel (4.4.39).
Tried twice with same result.
I'm running mga 5 server 32 bit and have a gts450.

CC: (none) => dag42


Note You need to log in before you can comment on or make changes to this bug.