Bug 20861 - Update request: kernel-4.4.68-1.mga5
Summary: Update request: kernel-4.4.68-1.mga5
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: advisory MGA5-64-OK MGA5-32-OK
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2017-05-15 20:27 CEST by Thomas Backlund
Modified: 2017-05-26 08:55 CEST (History)
6 users (show)

See Also:
Source RPM: kernel
CVE:
Status comment:


Attachments

Description Thomas Backlund 2017-05-15 20:27:54 CEST
More CVE fixes, including remote NFSD exploits, advisory will follow...

SRPMS:
kernel-4.4.68-1.mga5.src.rpm
kernel-userspace-headers-4.4.68-1.mga5.src.rpm

kmod-vboxadditions-5.1.22-3.mga5.src.rpm
kmod-virtualbox-5.1.22-3.mga5.src.rpm
kmod-xtables-addons-2.10-38.mga5.src.rpm



i586:
cpupower-4.4.68-1.mga5.i586.rpm
cpupower-devel-4.4.68-1.mga5.i586.rpm
kernel-desktop-4.4.68-1.mga5-1-1.mga5.i586.rpm
kernel-desktop586-4.4.68-1.mga5-1-1.mga5.i586.rpm
kernel-desktop586-devel-4.4.68-1.mga5-1-1.mga5.i586.rpm
kernel-desktop586-devel-latest-4.4.68-1.mga5.i586.rpm
kernel-desktop586-latest-4.4.68-1.mga5.i586.rpm
kernel-desktop-devel-4.4.68-1.mga5-1-1.mga5.i586.rpm
kernel-desktop-devel-latest-4.4.68-1.mga5.i586.rpm
kernel-desktop-latest-4.4.68-1.mga5.i586.rpm
kernel-doc-4.4.68-1.mga5.noarch.rpm
kernel-server-4.4.68-1.mga5-1-1.mga5.i586.rpm
kernel-server-devel-4.4.68-1.mga5-1-1.mga5.i586.rpm
kernel-server-devel-latest-4.4.68-1.mga5.i586.rpm
kernel-server-latest-4.4.68-1.mga5.i586.rpm
kernel-source-4.4.68-1.mga5-1-1.mga5.noarch.rpm
kernel-source-latest-4.4.68-1.mga5.noarch.rpm
kernel-userspace-headers-4.4.68-1.mga5.i586.rpm
perf-4.4.68-1.mga5.i586.rpm

vboxadditions-kernel-4.4.68-desktop-1.mga5-5.1.22-3.mga5.i586.rpm
vboxadditions-kernel-4.4.68-desktop586-1.mga5-5.1.22-3.mga5.i586.rpm
vboxadditions-kernel-4.4.68-server-1.mga5-5.1.22-3.mga5.i586.rpm
vboxadditions-kernel-desktop586-latest-5.1.22-3.mga5.i586.rpm
vboxadditions-kernel-desktop-latest-5.1.22-3.mga5.i586.rpm
vboxadditions-kernel-server-latest-5.1.22-3.mga5.i586.rpm

virtualbox-kernel-4.4.68-desktop-1.mga5-5.1.22-3.mga5.i586.rpm
virtualbox-kernel-4.4.68-desktop586-1.mga5-5.1.22-3.mga5.i586.rpm
virtualbox-kernel-4.4.68-server-1.mga5-5.1.22-3.mga5.i586.rpm
virtualbox-kernel-desktop586-latest-5.1.22-3.mga5.i586.rpm
virtualbox-kernel-desktop-latest-5.1.22-3.mga5.i586.rpm
virtualbox-kernel-server-latest-5.1.22-3.mga5.i586.rpm

xtables-addons-kernel-4.4.68-desktop-1.mga5-2.10-38.mga5.i586.rpm
xtables-addons-kernel-4.4.68-desktop586-1.mga5-2.10-38.mga5.i586.rpm
xtables-addons-kernel-4.4.68-server-1.mga5-2.10-38.mga5.i586.rpm
xtables-addons-kernel-desktop586-latest-2.10-38.mga5.i586.rpm
xtables-addons-kernel-desktop-latest-2.10-38.mga5.i586.rpm
xtables-addons-kernel-server-latest-2.10-38.mga5.i586.rpm



x86_64:
cpupower-4.4.68-1.mga5.x86_64.rpm
cpupower-devel-4.4.68-1.mga5.x86_64.rpm
kernel-desktop-4.4.68-1.mga5-1-1.mga5.x86_64.rpm
kernel-desktop-devel-4.4.68-1.mga5-1-1.mga5.x86_64.rpm
kernel-desktop-devel-latest-4.4.68-1.mga5.x86_64.rpm
kernel-desktop-latest-4.4.68-1.mga5.x86_64.rpm
kernel-doc-4.4.68-1.mga5.noarch.rpm
kernel-server-4.4.68-1.mga5-1-1.mga5.x86_64.rpm
kernel-server-devel-4.4.68-1.mga5-1-1.mga5.x86_64.rpm
kernel-server-devel-latest-4.4.68-1.mga5.x86_64.rpm
kernel-server-latest-4.4.68-1.mga5.x86_64.rpm
kernel-source-4.4.68-1.mga5-1-1.mga5.noarch.rpm
kernel-source-latest-4.4.68-1.mga5.noarch.rpm
kernel-userspace-headers-4.4.68-1.mga5.x86_64.rpm
perf-4.4.68-1.mga5.x86_64.rpm

vboxadditions-kernel-4.4.68-desktop-1.mga5-5.1.22-3.mga5.x86_64.rpm
vboxadditions-kernel-4.4.68-server-1.mga5-5.1.22-3.mga5.x86_64.rpm
vboxadditions-kernel-desktop-latest-5.1.22-3.mga5.x86_64.rpm
vboxadditions-kernel-server-latest-5.1.22-3.mga5.x86_64.rpm

virtualbox-kernel-4.4.68-desktop-1.mga5-5.1.22-3.mga5.x86_64.rpm
virtualbox-kernel-4.4.68-server-1.mga5-5.1.22-3.mga5.x86_64.rpm
virtualbox-kernel-desktop-latest-5.1.22-3.mga5.x86_64.rpm
virtualbox-kernel-server-latest-5.1.22-3.mga5.x86_64.rpm

xtables-addons-kernel-4.4.68-desktop-1.mga5-2.10-38.mga5.x86_64.rpm
xtables-addons-kernel-4.4.68-server-1.mga5-2.10-38.mga5.x86_64.rpm
xtables-addons-kernel-desktop-latest-2.10-38.mga5.x86_64.rpm
xtables-addons-kernel-server-latest-2.10-38.mga5.x86_64.rpm
Comment 1 Len Lawrence 2017-05-16 02:50:37 CEST
Installed on x86_64 UEFI Intel system with nvidia GTX 770.  The desktop is in good shape, virtualbox and common applications all functioning.
Comment 2 Len Lawrence 2017-05-16 10:36:11 CEST
x86_64 Intel with nvidia GTX970

Updates installed cleanly.  Rebooted to the desktop with rebuilt nvidia kmod.
Installed virtualbox and dkms_virtualbox.  vboxdrv and other vbox modules rebuilt and virtualbox guest launched OK.  Tried out some common applications like LibreOffice writer and vlc.  MCC and urpmi working fine.  firefox behaving itself.  Looks OK.
Comment 3 Len Lawrence 2017-05-16 11:05:50 CEST
i586 in virtualbox mga5.1 guest

Everything installed cleanly and the vbox rebooted to the Mate desktop.  So far everything is running fine.  Leaving the new kernel in place for a while.
Comment 4 Len Lawrence 2017-05-16 14:25:30 CEST
x86_64 Legacy boot Intel with nvidia 8700M GT

Updates went in smoothly - left out virtualbox kernel though.
Xfce running fine with nvidia340.101.
Comment 5 Len Lawrence 2017-05-16 17:58:38 CEST
x86_64 Brystalwell with twin nvidia GTX 965M

Installed pre-update virtualbox packages then updated the packages as listed.
All kmods built on the fly.  Rebooted to the Mate desktop.

nvidia 375.26 running.  Tried a few common desktop applications, including parole, vlc and gqview - everything looked good.  Installed a few extra packages.
Comment 6 James Kerr 2017-05-19 19:52:13 CEST
On mga5-64, packages installed cleanly:
- cpupower-4.4.68-1.mga5.x86_64
- kernel-desktop-4.4.68-1.mga5-1-1.mga5.x86_64
- kernel-desktop-latest-4.4.68-1.mga5.x86_64
- virtualbox-kernel-4.4.68-desktop-1.mga5-5.1.22-3.mga5.x86_64
- virtualbox-kernel-desktop-latest-5.1.22-3.mga5.x86_64

System re-booted normally:
$ uname -r
4.4.68-desktop-1.mga5

No regressions noted

vbox and clients (winxp, win7, cauldron) all OK

OK for mga5-64 on this system:
Dell product: Precision Tower 3620
Mobo: Dell model: 09WH54 
Card: Intel HD Graphics 530
CPU: Quad core Intel Core i7-6700 (-HT-MCP-)
Comment 7 William Kenney 2017-05-20 20:04:36 CEST
On real hardware, M5.1, KDE, 64-bit

initial install:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
kernel-desktop-devel-latest nvidia-current-kernel-desktop-latest

[root@localhost wilcal]# uname -a
Linux localhost 4.4.65-desktop-1.mga5 #1 SMP Fri Apr 28 14:15:56 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.4.65-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-5.1.22-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.1.22-2.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-5.1.22-1.mga5.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-5.1.22-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-5.1.22-2.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.1.22-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi kernel-desktop-devel-latest
Package kernel-desktop-devel-latest-4.4.65-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi nvidia-current-kernel-desktop-latest
Package nvidia-current-kernel-desktop-latest-352.79-10.mga5.nonfree.x86_64 is already installed
[wilcal@localhost ~]$ lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
        Subsystem: Gigabyte Technology Co., Ltd Device 3518
        Kernel driver in use: nvidia
        Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current

M5.1 i586 Gnome Live-CD runs as a Vbox client.
Boots to a working desktop. Common apps work.
Screen sizes are correct.

install or check:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
kernel-desktop-devel-latest nvidia-current-kernel-desktop-latest
from updates_testing

[root@localhost wilcal]# uname -a
Linux localhost 4.4.68-desktop-1.mga5 #1 SMP Sun May 14 17:56:12 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.4.68-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-5.1.22-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.1.22-3.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-5.1.22-1.mga5.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-5.1.22-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-5.1.22-3.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.1.22-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi kernel-desktop-devel-latest
Package kernel-desktop-devel-latest-4.4.68-1.mga5.x86_64 is already installed
[root@localhost wilcal]# urpmi nvidia-current-kernel-desktop-latest
Package nvidia-current-kernel-desktop-latest-352.79-10.mga5.nonfree.x86_64 is already installed
[wilcal@localhost ~]$ lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
        Subsystem: Gigabyte Technology Co., Ltd Device 3518
        Kernel driver in use: nvidia
        Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current

System boots to a working desktop. Common apps work.
Previously created M5 i586 Gnome Live-CD runs as a Vbox client.
M5.1 Gnome x86_64 Live-DVD runs as a Vbox client.
M5.1 x86_64 KDE CI, installs and updates as a Vbox client.

Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)

Looks good
Comment 8 David Walser 2017-05-20 21:03:52 CEST
I've been running this on my two PogoLinux workstations (Mageia 5 x86_64) at home ever since it was built, and it's been fine.  I think we can validate this now.
Comment 9 Thomas Backlund 2017-05-20 22:47:37 CEST
Advisory (also added to svn):

  This kernel update is based on upstream 4.4.68 and fixes atleast
  the following security issues:

  The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through
  4.10.11 allows remote attackers to cause a denial of service (system crash)
  via a long RPC reply, related to net/sunrpc/svc.c, fs/nfsd/nfs3xdr.c, and
  fs/nfsd/nfsxdr.c (CVE-2017-7645).

  The NFSv2 and NFSv3 server implementations in the Linux kernel through
  4.10.13 lack certain checks for the end of a buffer, which allows remote
  attackers to trigger pointer-arithmetic errors or possibly have unspecified
  other impact via crafted requests, related to fs/nfsd/nfs3xdr.c and
  fs/nfsd/nfsxdr.c (CVE-2017-7895).

  For other upstream fixes in this update, see the referenced changelogs.
references:
 - https://bugs.mageia.org/show_bug.cgi?id=20861
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.66
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.67
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.68
Comment 10 Brian Rockwell 2017-05-22 03:50:02 CEST
Intel i3 - laptop - wifi

$ uname -a
Linux localhost.localdomain 4.4.68-desktop-1.mga5 #1 SMP Sun May 14 18:41:19 UTC 2017 i686 i686 i686 GNU/Linux


tested libreoffice, chromium and firefox and sound are working as designed.
Comment 11 Dave Hodgins 2017-05-26 08:37:17 CEST
Testing of all kernels complete on real hardware and under vb.
Comment 12 Mageia Robot 2017-05-26 08:55:41 CEST
An update for this issue has been pushed to the Mageia Updates repository.

http://advisories.mageia.org/MGASA-2017-0149.html

Note You need to log in before you can comment on or make changes to this bug.