More CVE fixes, including remote NFSD exploits, advisory will follow... SRPMS: kernel-4.4.68-1.mga5.src.rpm kernel-userspace-headers-4.4.68-1.mga5.src.rpm kmod-vboxadditions-5.1.22-3.mga5.src.rpm kmod-virtualbox-5.1.22-3.mga5.src.rpm kmod-xtables-addons-2.10-38.mga5.src.rpm i586: cpupower-4.4.68-1.mga5.i586.rpm cpupower-devel-4.4.68-1.mga5.i586.rpm kernel-desktop-4.4.68-1.mga5-1-1.mga5.i586.rpm kernel-desktop586-4.4.68-1.mga5-1-1.mga5.i586.rpm kernel-desktop586-devel-4.4.68-1.mga5-1-1.mga5.i586.rpm kernel-desktop586-devel-latest-4.4.68-1.mga5.i586.rpm kernel-desktop586-latest-4.4.68-1.mga5.i586.rpm kernel-desktop-devel-4.4.68-1.mga5-1-1.mga5.i586.rpm kernel-desktop-devel-latest-4.4.68-1.mga5.i586.rpm kernel-desktop-latest-4.4.68-1.mga5.i586.rpm kernel-doc-4.4.68-1.mga5.noarch.rpm kernel-server-4.4.68-1.mga5-1-1.mga5.i586.rpm kernel-server-devel-4.4.68-1.mga5-1-1.mga5.i586.rpm kernel-server-devel-latest-4.4.68-1.mga5.i586.rpm kernel-server-latest-4.4.68-1.mga5.i586.rpm kernel-source-4.4.68-1.mga5-1-1.mga5.noarch.rpm kernel-source-latest-4.4.68-1.mga5.noarch.rpm kernel-userspace-headers-4.4.68-1.mga5.i586.rpm perf-4.4.68-1.mga5.i586.rpm vboxadditions-kernel-4.4.68-desktop-1.mga5-5.1.22-3.mga5.i586.rpm vboxadditions-kernel-4.4.68-desktop586-1.mga5-5.1.22-3.mga5.i586.rpm vboxadditions-kernel-4.4.68-server-1.mga5-5.1.22-3.mga5.i586.rpm vboxadditions-kernel-desktop586-latest-5.1.22-3.mga5.i586.rpm vboxadditions-kernel-desktop-latest-5.1.22-3.mga5.i586.rpm vboxadditions-kernel-server-latest-5.1.22-3.mga5.i586.rpm virtualbox-kernel-4.4.68-desktop-1.mga5-5.1.22-3.mga5.i586.rpm virtualbox-kernel-4.4.68-desktop586-1.mga5-5.1.22-3.mga5.i586.rpm virtualbox-kernel-4.4.68-server-1.mga5-5.1.22-3.mga5.i586.rpm virtualbox-kernel-desktop586-latest-5.1.22-3.mga5.i586.rpm virtualbox-kernel-desktop-latest-5.1.22-3.mga5.i586.rpm virtualbox-kernel-server-latest-5.1.22-3.mga5.i586.rpm xtables-addons-kernel-4.4.68-desktop-1.mga5-2.10-38.mga5.i586.rpm xtables-addons-kernel-4.4.68-desktop586-1.mga5-2.10-38.mga5.i586.rpm xtables-addons-kernel-4.4.68-server-1.mga5-2.10-38.mga5.i586.rpm xtables-addons-kernel-desktop586-latest-2.10-38.mga5.i586.rpm xtables-addons-kernel-desktop-latest-2.10-38.mga5.i586.rpm xtables-addons-kernel-server-latest-2.10-38.mga5.i586.rpm x86_64: cpupower-4.4.68-1.mga5.x86_64.rpm cpupower-devel-4.4.68-1.mga5.x86_64.rpm kernel-desktop-4.4.68-1.mga5-1-1.mga5.x86_64.rpm kernel-desktop-devel-4.4.68-1.mga5-1-1.mga5.x86_64.rpm kernel-desktop-devel-latest-4.4.68-1.mga5.x86_64.rpm kernel-desktop-latest-4.4.68-1.mga5.x86_64.rpm kernel-doc-4.4.68-1.mga5.noarch.rpm kernel-server-4.4.68-1.mga5-1-1.mga5.x86_64.rpm kernel-server-devel-4.4.68-1.mga5-1-1.mga5.x86_64.rpm kernel-server-devel-latest-4.4.68-1.mga5.x86_64.rpm kernel-server-latest-4.4.68-1.mga5.x86_64.rpm kernel-source-4.4.68-1.mga5-1-1.mga5.noarch.rpm kernel-source-latest-4.4.68-1.mga5.noarch.rpm kernel-userspace-headers-4.4.68-1.mga5.x86_64.rpm perf-4.4.68-1.mga5.x86_64.rpm vboxadditions-kernel-4.4.68-desktop-1.mga5-5.1.22-3.mga5.x86_64.rpm vboxadditions-kernel-4.4.68-server-1.mga5-5.1.22-3.mga5.x86_64.rpm vboxadditions-kernel-desktop-latest-5.1.22-3.mga5.x86_64.rpm vboxadditions-kernel-server-latest-5.1.22-3.mga5.x86_64.rpm virtualbox-kernel-4.4.68-desktop-1.mga5-5.1.22-3.mga5.x86_64.rpm virtualbox-kernel-4.4.68-server-1.mga5-5.1.22-3.mga5.x86_64.rpm virtualbox-kernel-desktop-latest-5.1.22-3.mga5.x86_64.rpm virtualbox-kernel-server-latest-5.1.22-3.mga5.x86_64.rpm xtables-addons-kernel-4.4.68-desktop-1.mga5-2.10-38.mga5.x86_64.rpm xtables-addons-kernel-4.4.68-server-1.mga5-2.10-38.mga5.x86_64.rpm xtables-addons-kernel-desktop-latest-2.10-38.mga5.x86_64.rpm xtables-addons-kernel-server-latest-2.10-38.mga5.x86_64.rpm
Installed on x86_64 UEFI Intel system with nvidia GTX 770. The desktop is in good shape, virtualbox and common applications all functioning.
CC: (none) => tarazed25
x86_64 Intel with nvidia GTX970 Updates installed cleanly. Rebooted to the desktop with rebuilt nvidia kmod. Installed virtualbox and dkms_virtualbox. vboxdrv and other vbox modules rebuilt and virtualbox guest launched OK. Tried out some common applications like LibreOffice writer and vlc. MCC and urpmi working fine. firefox behaving itself. Looks OK.
i586 in virtualbox mga5.1 guest Everything installed cleanly and the vbox rebooted to the Mate desktop. So far everything is running fine. Leaving the new kernel in place for a while.
x86_64 Legacy boot Intel with nvidia 8700M GT Updates went in smoothly - left out virtualbox kernel though. Xfce running fine with nvidia340.101.
x86_64 Brystalwell with twin nvidia GTX 965M Installed pre-update virtualbox packages then updated the packages as listed. All kmods built on the fly. Rebooted to the Mate desktop. nvidia 375.26 running. Tried a few common desktop applications, including parole, vlc and gqview - everything looked good. Installed a few extra packages.
On mga5-64, packages installed cleanly: - cpupower-4.4.68-1.mga5.x86_64 - kernel-desktop-4.4.68-1.mga5-1-1.mga5.x86_64 - kernel-desktop-latest-4.4.68-1.mga5.x86_64 - virtualbox-kernel-4.4.68-desktop-1.mga5-5.1.22-3.mga5.x86_64 - virtualbox-kernel-desktop-latest-5.1.22-3.mga5.x86_64 System re-booted normally: $ uname -r 4.4.68-desktop-1.mga5 No regressions noted vbox and clients (winxp, win7, cauldron) all OK OK for mga5-64 on this system: Dell product: Precision Tower 3620 Mobo: Dell model: 09WH54 Card: Intel HD Graphics 530 CPU: Quad core Intel Core i7-6700 (-HT-MCP-)
CC: (none) => jim
On real hardware, M5.1, KDE, 64-bit initial install: kernel-desktop-latest virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo kernel-desktop-devel-latest nvidia-current-kernel-desktop-latest [root@localhost wilcal]# uname -a Linux localhost 4.4.65-desktop-1.mga5 #1 SMP Fri Apr 28 14:15:56 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.4.65-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox Package virtualbox-5.1.22-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.22-2.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi dkms-virtualbox Package dkms-virtualbox-5.1.22-1.mga5.noarch is already installed [root@localhost wilcal]# urpmi virtualbox-guest-additions Package virtualbox-guest-additions-5.1.22-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest Package virtualbox-kernel-desktop-latest-5.1.22-2.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi x11-driver-video-vboxvideo Package x11-driver-video-vboxvideo-5.1.22-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi kernel-desktop-devel-latest Package kernel-desktop-devel-latest-4.4.65-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi nvidia-current-kernel-desktop-latest Package nvidia-current-kernel-desktop-latest-352.79-10.mga5.nonfree.x86_64 is already installed [wilcal@localhost ~]$ lspci -k 01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1) Subsystem: Gigabyte Technology Co., Ltd Device 3518 Kernel driver in use: nvidia Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current M5.1 i586 Gnome Live-CD runs as a Vbox client. Boots to a working desktop. Common apps work. Screen sizes are correct. install or check: kernel-desktop-latest virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo kernel-desktop-devel-latest nvidia-current-kernel-desktop-latest from updates_testing [root@localhost wilcal]# uname -a Linux localhost 4.4.68-desktop-1.mga5 #1 SMP Sun May 14 17:56:12 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.4.68-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox Package virtualbox-5.1.22-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.22-3.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi dkms-virtualbox Package dkms-virtualbox-5.1.22-1.mga5.noarch is already installed [root@localhost wilcal]# urpmi virtualbox-guest-additions Package virtualbox-guest-additions-5.1.22-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest Package virtualbox-kernel-desktop-latest-5.1.22-3.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi x11-driver-video-vboxvideo Package x11-driver-video-vboxvideo-5.1.22-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi kernel-desktop-devel-latest Package kernel-desktop-devel-latest-4.4.68-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi nvidia-current-kernel-desktop-latest Package nvidia-current-kernel-desktop-latest-352.79-10.mga5.nonfree.x86_64 is already installed [wilcal@localhost ~]$ lspci -k 01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1) Subsystem: Gigabyte Technology Co., Ltd Device 3518 Kernel driver in use: nvidia Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current System boots to a working desktop. Common apps work. Previously created M5 i586 Gnome Live-CD runs as a Vbox client. M5.1 Gnome x86_64 Live-DVD runs as a Vbox client. M5.1 x86_64 KDE CI, installs and updates as a Vbox client. Test platform: Intel Core i7-2600K Sandy Bridge 3.4GHz GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB RTL8111/8168B PCI Express 1Gbit Ethernet DRAM 16GB (4 x 4GB) Looks good
CC: (none) => wilcal.int
I've been running this on my two PogoLinux workstations (Mageia 5 x86_64) at home ever since it was built, and it's been fine. I think we can validate this now.
Advisory (also added to svn): This kernel update is based on upstream 4.4.68 and fixes atleast the following security issues: The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a denial of service (system crash) via a long RPC reply, related to net/sunrpc/svc.c, fs/nfsd/nfs3xdr.c, and fs/nfsd/nfsxdr.c (CVE-2017-7645). The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possibly have unspecified other impact via crafted requests, related to fs/nfsd/nfs3xdr.c and fs/nfsd/nfsxdr.c (CVE-2017-7895). For other upstream fixes in this update, see the referenced changelogs. references: - https://bugs.mageia.org/show_bug.cgi?id=20861 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.66 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.67 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.68
Whiteboard: (none) => advisory
Intel i3 - laptop - wifi $ uname -a Linux localhost.localdomain 4.4.68-desktop-1.mga5 #1 SMP Sun May 14 18:41:19 UTC 2017 i686 i686 i686 GNU/Linux tested libreoffice, chromium and firefox and sound are working as designed.
CC: (none) => brtians1
Testing of all kernels complete on real hardware and under vb.
Keywords: (none) => validated_updateWhiteboard: advisory => advisory MGA5-64-OK MGA5-32-OKCC: (none) => davidwhodgins, sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. http://advisories.mageia.org/MGASA-2017-0149.html
Resolution: (none) => FIXEDStatus: NEW => RESOLVED