Bug 21708 - Update request: kernel-4.9.50-1.mga6
Summary: Update request: kernel-4.9.50-1.mga6
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA6-64-OK MGA6-32-OK
Keywords: advisory, validated_update
Depends on:
Blocks: 21498
  Show dependency treegraph
 
Reported: 2017-09-14 19:58 CEST by Thomas Backlund
Modified: 2017-09-16 10:25 CEST (History)
4 users (show)

See Also:
Source RPM: kernel
CVE:
Status comment:


Attachments

Description Thomas Backlund 2017-09-14 19:58:07 CEST
Updated kernels fixing various security issues, including the "BlueBorne" bluetooth remote code execution CVE-2017-1000251 ...

Advisory will follow...


SRPMS:
kernel-4.9.50-1.mga6.src.rpm
kernel-userspace-headers-4.9.50-1.mga6.src.rpm
kmod-vboxadditions-5.1.26-4.mga6.src.rpm
kmod-virtualbox-5.1.26-4.mga6.src.rpm
kmod-xtables-addons-2.12-43.mga6.src.rpm


i586:
cpupower-4.9.50-1.mga6.i586.rpm
cpupower-devel-4.9.50-1.mga6.i586.rpm
kernel-desktop-4.9.50-1.mga6-1-1.mga6.i586.rpm
kernel-desktop586-4.9.50-1.mga6-1-1.mga6.i586.rpm
kernel-desktop586-devel-4.9.50-1.mga6-1-1.mga6.i586.rpm
kernel-desktop586-devel-latest-4.9.50-1.mga6.i586.rpm
kernel-desktop586-latest-4.9.50-1.mga6.i586.rpm
kernel-desktop-devel-4.9.50-1.mga6-1-1.mga6.i586.rpm
kernel-desktop-devel-latest-4.9.50-1.mga6.i586.rpm
kernel-desktop-latest-4.9.50-1.mga6.i586.rpm
kernel-doc-4.9.50-1.mga6.noarch.rpm
kernel-server-4.9.50-1.mga6-1-1.mga6.i586.rpm
kernel-server-devel-4.9.50-1.mga6-1-1.mga6.i586.rpm
kernel-server-devel-latest-4.9.50-1.mga6.i586.rpm
kernel-server-latest-4.9.50-1.mga6.i586.rpm
kernel-source-4.9.50-1.mga6-1-1.mga6.noarch.rpm
kernel-source-latest-4.9.50-1.mga6.noarch.rpm
kernel-userspace-headers-4.9.50-1.mga6.i586.rpm
perf-4.9.50-1.mga6.i586.rpm

vboxadditions-kernel-4.9.50-desktop-1.mga6-5.1.26-4.mga6.i586.rpm
vboxadditions-kernel-4.9.50-desktop586-1.mga6-5.1.26-4.mga6.i586.rpm
vboxadditions-kernel-4.9.50-server-1.mga6-5.1.26-4.mga6.i586.rpm
vboxadditions-kernel-desktop586-latest-5.1.26-4.mga6.i586.rpm
vboxadditions-kernel-desktop-latest-5.1.26-4.mga6.i586.rpm
vboxadditions-kernel-server-latest-5.1.26-4.mga6.i586.rpm

virtualbox-kernel-4.9.50-desktop-1.mga6-5.1.26-4.mga6.i586.rpm
virtualbox-kernel-4.9.50-desktop586-1.mga6-5.1.26-4.mga6.i586.rpm
virtualbox-kernel-4.9.50-server-1.mga6-5.1.26-4.mga6.i586.rpm
virtualbox-kernel-desktop586-latest-5.1.26-4.mga6.i586.rpm
virtualbox-kernel-desktop-latest-5.1.26-4.mga6.i586.rpm
virtualbox-kernel-server-latest-5.1.26-4.mga6.i586.rpm

xtables-addons-kernel-4.9.50-desktop-1.mga6-2.12-43.mga6.i586.rpm
xtables-addons-kernel-4.9.50-desktop586-1.mga6-2.12-43.mga6.i586.rpm
xtables-addons-kernel-4.9.50-server-1.mga6-2.12-43.mga6.i586.rpm
xtables-addons-kernel-desktop586-latest-2.12-43.mga6.i586.rpm
xtables-addons-kernel-desktop-latest-2.12-43.mga6.i586.rpm
xtables-addons-kernel-server-latest-2.12-43.mga6.i586.rpm


x86_64:
cpupower-4.9.50-1.mga6.x86_64.rpm
cpupower-devel-4.9.50-1.mga6.x86_64.rpm
kernel-desktop-4.9.50-1.mga6-1-1.mga6.x86_64.rpm
kernel-desktop-devel-4.9.50-1.mga6-1-1.mga6.x86_64.rpm
kernel-desktop-devel-latest-4.9.50-1.mga6.x86_64.rpm
kernel-desktop-latest-4.9.50-1.mga6.x86_64.rpm
kernel-doc-4.9.50-1.mga6.noarch.rpm
kernel-server-4.9.50-1.mga6-1-1.mga6.x86_64.rpm
kernel-server-devel-4.9.50-1.mga6-1-1.mga6.x86_64.rpm
kernel-server-devel-latest-4.9.50-1.mga6.x86_64.rpm
kernel-server-latest-4.9.50-1.mga6.x86_64.rpm
kernel-source-4.9.50-1.mga6-1-1.mga6.noarch.rpm
kernel-source-latest-4.9.50-1.mga6.noarch.rpm
kernel-userspace-headers-4.9.50-1.mga6.x86_64.rpm
perf-4.9.50-1.mga6.x86_64.rpm

vboxadditions-kernel-4.9.50-desktop-1.mga6-5.1.26-4.mga6.x86_64.rpm
vboxadditions-kernel-4.9.50-server-1.mga6-5.1.26-4.mga6.x86_64.rpm
vboxadditions-kernel-desktop-latest-5.1.26-4.mga6.x86_64.rpm
vboxadditions-kernel-server-latest-5.1.26-4.mga6.x86_64.rpm

virtualbox-kernel-4.9.50-desktop-1.mga6-5.1.26-4.mga6.x86_64.rpm
virtualbox-kernel-4.9.50-server-1.mga6-5.1.26-4.mga6.x86_64.rpm
virtualbox-kernel-desktop-latest-5.1.26-4.mga6.x86_64.rpm
virtualbox-kernel-server-latest-5.1.26-4.mga6.x86_64.rpm

xtables-addons-kernel-4.9.50-desktop-1.mga6-2.12-43.mga6.x86_64.rpm
xtables-addons-kernel-4.9.50-server-1.mga6-2.12-43.mga6.x86_64.rpm
xtables-addons-kernel-desktop-latest-2.12-43.mga6.x86_64.rpm
xtables-addons-kernel-server-latest-2.12-43.mga6.x86_64.rpm
Thomas Backlund 2017-09-14 20:17:47 CEST

Blocks: (none) => 21498

Comment 1 William Kenney 2017-09-15 00:50:08 CEST
In a Vbox client, M6, Plasma, 64bit

Testing: kernel-desktop-latest vboxadditions-kernel-desktop-latest

[root@localhost wilcal]# uname -a
Linux localhost 4.9.43-desktop-1.mga6 #1 SMP Sun Aug 13 15:52:35 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.9.43-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.1.26-2.mga6.x86_64 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

Installed kernel-desktop-latest vboxadditions-kernel-desktop-latest from updates testing

Reboot client

[root@localhost wilcal]# uname -a
Linux localhost 4.9.50-desktop-1.mga6 #1 SMP Wed Sep 13 23:14:20 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.9.50-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.1.26-4.mga6.x86_64 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

CC: (none) => wilcal.int

Comment 2 William Kenney 2017-09-15 01:00:22 CEST
In a Vbox client, M6, Plasma, 32bit

Testing: kernel-desktop-latest vboxadditions-kernel-desktop-latest

[root@localhost wilcal]# uname -a
Linux localhost 4.9.43-desktop-1.mga6 #1 SMP Sun Aug 13 16:29:48 UTC 2017 i686 i686 i686 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.9.43-1.mga6.i586 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.1.26-2.mga6.i586 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

Installed kernel-desktop-latest vboxadditions-kernel-desktop-latest from updates testing

Reboot client

[root@localhost wilcal]# uname -a
Linux localhost 4.9.50-desktop-1.mga6 #1 SMP Wed Sep 13 23:15:15 UTC 2017 i686 i686 i686 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.9.50-1.mga6.i586 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.1.26-4.mga6.i586 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.
Comment 3 William Kenney 2017-09-15 04:00:48 CEST
On real hardware, M6, Plasma, 64-bit

initial install:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
kernel-desktop-devel-latest dkms-nvidia-current

[root@localhost wilcal]# uname -a
Linux localhost 4.9.43-desktop-1.mga6 #1 SMP Sun Aug 13 15:52:35 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.9.43-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-5.1.26-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.1.26-2.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-5.1.26-1.mga6.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-5.1.26-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-5.1.26-2.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.1.26-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi kernel-desktop-devel-latest
Package kernel-desktop-devel-latest-4.9.43-1.mga6.x86_64 is already installed
Marking kernel-desktop-devel-latest as manually installed, it won't be auto-orphaned
writing /var/lib/rpm/installed-through-deps.list
[root@localhost wilcal]# urpmi dkms-nvidia-current
Package dkms-nvidia-current-384.59-1.mga6.nonfree.x86_64 is already installed
[wilcal@localhost ~]$ lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
        Subsystem: Gigabyte Technology Co., Ltd Device 3518
        Kernel driver in use: nvidia
        Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current

M5.1 i586 Gnome Live-DVD runs as a Vbox client.
Boots to a working desktop. Common apps work.
Screen sizes are correct.

update:
kernel-desktop-latest
virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox
virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo
kernel-desktop-devel-latest dkms-nvidia-current
from updates_testing

[root@localhost wilcal]# uname -a
Linux localhost 4.9.50-desktop-1.mga6 #1 SMP Wed Sep 13 23:14:20 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.9.50-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox
Package virtualbox-5.1.26-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-5.1.26-4.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-virtualbox
Package dkms-virtualbox-5.1.26-1.mga6.noarch is already installed
[root@localhost wilcal]# urpmi virtualbox-guest-additions
Package virtualbox-guest-additions-5.1.26-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest
Package virtualbox-kernel-desktop-latest-5.1.26-4.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi x11-driver-video-vboxvideo
Package x11-driver-video-vboxvideo-5.1.26-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi kernel-desktop-devel-latest
Package kernel-desktop-devel-latest-4.9.50-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi dkms-nvidia-current
Package dkms-nvidia-current-384.59-1.mga6.nonfree.x86_64 is already installed
[wilcal@localhost ~]$ lspci -k
01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1)
        Subsystem: Gigabyte Technology Co., Ltd Device 3518
        Kernel driver in use: nvidia
        Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current

M5.1 i586 Gnome LiveDVD still runs as a Vbox client.

M6 x86_64 Gnome LiveDVD runs as a Vbox client.
Boots to a working desktop. Common apps work.
Screen sizes are correct.

M6 x86_64 Plasma LiveDVD installs and runs as a Vbox client.
Updates then reboots back to a working desktop.
Screen sizes are correct.

Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)
Looks good
Comment 4 Thomas Andrews 2017-09-15 14:45:18 CEST
Testing 32-bit server kernel on an HP 6550b laptop (i3, 8GB, Intel graphics, Intel wifi). This laptop is supposed to have Bluetooth capability, but I have never used it.

Running Plasma, everything looks good. Wifi, display, Firefox, Gimp, all look as they should. No regressions noted.

Will test 64-bit later today.

CC: (none) => andrewsfarm

Comment 5 Dave Hodgins 2017-09-15 16:06:46 CEST
Tested on both real hardware, and under vb, both arches. Adding the OKs.

CC: (none) => davidwhodgins
Whiteboard: (none) => MGA6-64-OK MGA6-32-OK

Comment 6 Dave Hodgins 2017-09-15 16:08:17 CEST
Tested on both real hardware, and under vb, both arches. Adding the OKs.
Comment 7 Thomas Backlund 2017-09-15 19:36:27 CEST
Advisory:

  This kernel update is based on upstream 4.9.50 and fixes atleast the
  following security issues:

  net/xfrm/xfrm_policy.c in the Linux kernel through 4.12.3, when 
  CONFIG_XFRM_MIGRATE is enabled, does not ensure that the dir value of
  xfrm_userpolicy_id is XFRM_POLICY_MAX or less, which allows local users
  to cause a denial of service (out-of-bounds access) or possibly have
  unspecified other impact via an XFRM_MSG_MIGRATE xfrm Netlink message
  (CVE-2017-11600).

  The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen
  might allow local OS guest users to corrupt block device data streams
  and consequently obtain sensitive memory information, cause a denial of
  service, or gain host OS privileges by leveraging incorrect block IO
  merge-ability calculation (CVE-2017-12134 / XSA-229).

  The XFS_IS_REALTIME_INODE macro in fs/xfs/xfs_linux.h in the Linux kernel
  before 4.13.2 does not verify that a filesystem has a realtime device,
  which allows local users to cause a denial of service (NULL pointer
  dereference and OOPS) via vectors related to setting an RHINHERIT flag
  on a directory (CVE-2017-14340).

  The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the
  Linux kernel version 3.3-rc1 and up to and including 4.13.1, are vulnerable
  to a stack overflow vulnerability in the processing of L2CAP configuration
  responses resulting in Remote code execution in kernel space
  (CVE-2017-1000251).

  For other upstream fixes in this update, read the referenced changelogs.
references:
 - https://bugs.mageia.org/show_bug.cgi?id=21708
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.44
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.45
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.46
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.47
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.48
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.49
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.50

Whiteboard: MGA6-64-OK MGA6-32-OK => MGA6-64-OK MGA6-32-OK advisory

Dave Hodgins 2017-09-15 20:59:38 CEST

Keywords: (none) => advisory, validated_update
Whiteboard: MGA6-64-OK MGA6-32-OK advisory => MGA6-64-OK MGA6-32-OK
CC: (none) => sysadmin-bugs

Comment 8 Thomas Andrews 2017-09-16 03:08:13 CEST
Not quite quick enough, but I did a couple of more tests:

Same hardware as Comment 4, 64-bit desktop kernel, this time with VirtualBox, too. All looks good.

Real hardware, Athlon X2 7750, 8GB, nvidia 340 graphics, Atheros wifi. Testing 64-bit server kernel, with VirtualBox. Again, all looks good.
Comment 9 Mageia Robot 2017-09-16 10:25:50 CEST
An update for this issue has been pushed to the Mageia Updates repository.

http://advisories.mageia.org/MGASA-2017-0342.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.