Updated virtualbox packages fix security vulnerabilities This update provides the virtualbox 5.1.30 maintenance release, fixing security and other issues: In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack (CVE-2017-3730). OpenSSL is vulnerable to a denial of service, caused by an out-of-bounds read when using a specific cipher. By sending specially crafted truncated packets, a remote attacker could exploit this vulnerability using CHACHA20/POLY1305 to cause the application to crash (CVE-2017-3731). OpenSSL could allow a remote attacker to obtain sensitive information, caused by a propagation error in the BN_mod_exp() function. An attacker could exploit this vulnerability to obtain information about the private key (CVE-2017-3732). During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected (CVE-2017-3733) A local user can exploit a flaw in the Oracle VM VirtualBox Core component to partially access data, partially modify data, and deny service (CVE-2017-10392, CVE-2017-10407, CVE-2017-10408). A local user can exploit a flaw in the Oracle VM VirtualBox Core component to partially access data, partially modify data, and partially deny service (CVE-2017-10428). For other fixes in this update see the referenced changelog. References https://www.virtualbox.org/wiki/Changelog-5.1#v30 SRPMS: 5/core virtualbox-5.1.30-1.mga5 kmod-vboxadditions-5.1.30-1.mga5 kmod-virtualbox-5.1.30-1.mga5 6/core virtualbox-5.1.30-1.mga6 kmod-vboxadditions-5.1.30-1.mga6 kmod-virtualbox-5.1.30-1.mga6
Mga5: i586: dkms-vboxadditions-5.1.30-1.mga5.noarch.rpm dkms-virtualbox-5.1.30-1.mga5.noarch.rpm python-virtualbox-5.1.30-1.mga5.i586.rpm virtualbox-5.1.30-1.mga5.i586.rpm virtualbox-devel-5.1.30-1.mga5.i586.rpm virtualbox-doc-5.1.30-1.mga5.noarch.rpm virtualbox-guest-additions-5.1.30-1.mga5.i586.rpm x11-driver-video-vboxvideo-5.1.30-1.mga5.i586.rpm x86_64: dkms-vboxadditions-5.1.30-1.mga5.noarch.rpm dkms-virtualbox-5.1.30-1.mga5.noarch.rpm python-virtualbox-5.1.30-1.mga5.x86_64.rpm virtualbox-5.1.30-1.mga5.x86_64.rpm virtualbox-devel-5.1.30-1.mga5.x86_64.rpm virtualbox-doc-5.1.30-1.mga5.noarch.rpm virtualbox-guest-additions-5.1.30-1.mga5.x86_64.rpm x11-driver-video-vboxvideo-5.1.30-1.mga5.x86_64.rpm Note: mga5 kmods will be built after current 4.4.92 kernel is validated and pushed
Depends on: (none) => 21852Whiteboard: (none) => MGA5TOO
Mga6: i586: dkms-vboxadditions-5.1.30-1.mga6.noarch.rpm dkms-virtualbox-5.1.30-1.mga6.noarch.rpm python-virtualbox-5.1.30-1.mga6.i586.rpm virtualbox-5.1.30-1.mga6.i586.rpm virtualbox-devel-5.1.30-1.mga6.i586.rpm virtualbox-doc-5.1.30-1.mga6.noarch.rpm virtualbox-guest-additions-5.1.30-1.mga6.i586.rpm x11-driver-video-vboxvideo-5.1.30-1.mga6.i586.rpm vboxadditions-kernel-4.9.56-desktop-1.mga6-5.1.30-1.mga6.i586.rpm vboxadditions-kernel-4.9.56-desktop586-1.mga6-5.1.30-1.mga6.i586.rpm vboxadditions-kernel-4.9.56-server-1.mga6-5.1.30-1.mga6.i586.rpm vboxadditions-kernel-desktop586-latest-5.1.30-1.mga6.i586.rpm vboxadditions-kernel-desktop-latest-5.1.30-1.mga6.i586.rpm vboxadditions-kernel-server-latest-5.1.30-1.mga6.i586.rpm virtualbox-kernel-4.9.56-desktop-1.mga6-5.1.30-1.mga6.i586.rpm virtualbox-kernel-4.9.56-desktop586-1.mga6-5.1.30-1.mga6.i586.rpm virtualbox-kernel-4.9.56-server-1.mga6-5.1.30-1.mga6.i586.rpm virtualbox-kernel-desktop586-latest-5.1.30-1.mga6.i586.rpm virtualbox-kernel-desktop-latest-5.1.30-1.mga6.i586.rpm virtualbox-kernel-server-latest-5.1.30-1.mga6.i586.rpm x86_64: dkms-vboxadditions-5.1.30-1.mga6.noarch.rpm dkms-virtualbox-5.1.30-1.mga6.noarch.rpm python-virtualbox-5.1.30-1.mga6.x86_64.rpm virtualbox-5.1.30-1.mga6.x86_64.rpm virtualbox-devel-5.1.30-1.mga6.x86_64.rpm virtualbox-doc-5.1.30-1.mga6.noarch.rpm virtualbox-guest-additions-5.1.30-1.mga6.x86_64.rpm x11-driver-video-vboxvideo-5.1.30-1.mga6.x86_64.rpm vboxadditions-kernel-4.9.56-desktop-1.mga6-5.1.30-1.mga6.x86_64.rpm vboxadditions-kernel-4.9.56-server-1.mga6-5.1.30-1.mga6.x86_64.rpm vboxadditions-kernel-desktop-latest-5.1.30-1.mga6.x86_64.rpm vboxadditions-kernel-server-latest-5.1.30-1.mga6.x86_64.rpm virtualbox-kernel-4.9.56-desktop-1.mga6-5.1.30-1.mga6.x86_64.rpm virtualbox-kernel-4.9.56-server-1.mga6-5.1.30-1.mga6.x86_64.rpm virtualbox-kernel-desktop-latest-5.1.30-1.mga6.x86_64.rpm virtualbox-kernel-server-latest-5.1.30-1.mga6.x86_64.rpm
on mga6-64 $ uname -r 4.9.56-desktop-1.mga6 Packages installed cleanly: - virtualbox-5.1.30-1.mga6.x86_64 - virtualbox-kernel-4.9.56-desktop-1.mga6-5.1.30-1.mga6.x86_64 - virtualbox-kernel-desktop-latest-5.1.30-1.mga6.x86_64 extension pack upgraded cleanly virtualbox and client launched normally looks OK for mga6-64
CC: (none) => jim
on mga6-32 in a vbox VM $ uname -r 4.9.56-desktop-1.mga6 Packages installed cleanly: - vboxadditions-kernel-4.9.56-desktop-1.mga6-5.1.30-1.mga6.i586 - vboxadditions-kernel-desktop-latest-5.1.30-1.mga6.i586 - virtualbox-guest-additions-5.1.30-1.mga6.i586 - x11-driver-video-vboxvideo-5.1.30-1.mga6.i586 VM re-booted normally No regressions noted looks OK for mga6-32 in a vbox VM
Installed and tested without issues. Host System: Mageia 5, x86_64, Plasma DE, Intel CPU, nVidia GPU with proprietary driver nvidia340. Guest Systems: - Windows XP - Windows 7 - Windows 10 - Mageia 5, x86_64, Plasma DE - Mageia 6, x86_64, Plasma DE Tests involved booting, updating, rebooting, browsing with firefox and running some other programs. All seems OK. No regressions. $ uname -a Linux marte 4.4.92-desktop-1.mga5 #1 SMP Thu Oct 12 20:14:45 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux $ rpm -qa | egrep 'kernel|vbox|virtualbox|dkms' | sort dkms-2.0.19-34.1.mga5 dkms-minimal-2.0.19-34.1.mga5 dkms-nvidia340-340.101-1.mga5.nonfree dkms-virtualbox-5.1.30-1.mga5 kernel-desktop-4.4.92-1.mga5-1-1.mga5 kernel-desktop-devel-4.4.92-1.mga5-1-1.mga5 kernel-desktop-devel-latest-4.4.92-1.mga5 kernel-desktop-latest-4.4.92-1.mga5 kernel-firmware-20160409-1.mga5 kernel-firmware-nonfree-20160914-1.mga5.nonfree kernel-userspace-headers-4.4.92-1.mga5 nvidia340-kernel-desktop-latest-340.96-6.mga5.nonfree virtualbox-5.1.30-1.mga5 virtualbox-doc-5.1.30-1.mga5
CC: (none) => mageia
Mga5 kmods: i586: vboxadditions-kernel-4.4.92-desktop-1.mga5-5.1.30-1.mga5.i586.rpm vboxadditions-kernel-4.4.92-desktop586-1.mga5-5.1.30-1.mga5.i586.rpm vboxadditions-kernel-4.4.92-server-1.mga5-5.1.30-1.mga5.i586.rpm vboxadditions-kernel-desktop586-latest-5.1.30-1.mga5.i586.rpm vboxadditions-kernel-desktop-latest-5.1.30-1.mga5.i586.rpm vboxadditions-kernel-server-latest-5.1.30-1.mga5.i586.rpm virtualbox-kernel-4.4.92-desktop-1.mga5-5.1.30-1.mga5.i586.rpm virtualbox-kernel-4.4.92-desktop586-1.mga5-5.1.30-1.mga5.i586.rpm virtualbox-kernel-4.4.92-server-1.mga5-5.1.30-1.mga5.i586.rpm virtualbox-kernel-desktop586-latest-5.1.30-1.mga5.i586.rpm virtualbox-kernel-desktop-latest-5.1.30-1.mga5.i586.rpm virtualbox-kernel-server-latest-5.1.30-1.mga5.i586.rpm x86_64: vboxadditions-kernel-4.4.92-desktop-1.mga5-5.1.30-1.mga5.x86_64.rpm vboxadditions-kernel-4.4.92-server-1.mga5-5.1.30-1.mga5.x86_64.rpm vboxadditions-kernel-desktop-latest-5.1.30-1.mga5.x86_64.rpm vboxadditions-kernel-server-latest-5.1.30-1.mga5.x86_64.rpm virtualbox-kernel-4.4.92-desktop-1.mga5-5.1.30-1.mga5.x86_64.rpm virtualbox-kernel-4.4.92-server-1.mga5-5.1.30-1.mga5.x86_64.rpm virtualbox-kernel-desktop-latest-5.1.30-1.mga5.x86_64.rpm virtualbox-kernel-server-latest-5.1.30-1.mga5.x86_64.rpm
On mga5-64 $ uname -r 4.4.92-desktop-1.mga5 packages installed cleanly: - virtualbox-5.1.30-1.mga5.x86_64 - virtualbox-doc-5.1.30-1.mga5.noarch - virtualbox-kernel-4.4.92-desktop-1.mga5-5.1.30-1.mga5.x86_64 - virtualbox-kernel-desktop-latest-5.1.30-1.mga5.x86_64 Virtualbox and client launched normally Extension pack installed cleanly looks OK for mga5-64
on mga5-32 in a vbox VM $ uname -r 4.4.92-desktop-1.mga5 packages installed cleanly: - vboxadditions-kernel-4.4.92-desktop-1.mga5-5.1.30-1.mga5.i586 - vboxadditions-kernel-desktop-latest-5.1.30-1.mga5.i586 - virtualbox-guest-additions-5.1.30-1.mga5.i586 - x11-driver-video-vboxvideo-5.1.30-1.mga5.i586 VM re-booted normally No regressions noted looks OK for mga5-32 in a vbox VM
On real hardware, M6, Plasma, 64-bit initial install: kernel-desktop-latest virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo kernel-desktop-devel-latest dkms-nvidia-current [root@localhost wilcal]# uname -a Linux localhost 4.9.56-desktop-1.mga6 #1 SMP Thu Oct 12 22:55:31 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.9.56-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox Package virtualbox-5.1.26-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.26-6.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi dkms-virtualbox Package dkms-virtualbox-5.1.26-1.mga6.noarch is already installed [root@localhost wilcal]# urpmi virtualbox-guest-additions Package virtualbox-guest-additions-5.1.26-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest Package virtualbox-kernel-desktop-latest-5.1.26-6.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi x11-driver-video-vboxvideo Package x11-driver-video-vboxvideo-5.1.26-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi kernel-desktop-devel-latest Package kernel-desktop-devel-latest-4.9.56-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi dkms-nvidia-current Package dkms-nvidia-current-384.59-1.mga6.nonfree.x86_64 is already installed [wilcal@localhost ~]$ lspci -k 01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1) Subsystem: Gigabyte Technology Co., Ltd Device 3518 Kernel driver in use: nvidia Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current M6 i586 Xfce LiveDVD runs as a Vbox client. Boots to a working desktop. Common apps work. Screen sizes are correct. install or check: kernel-desktop-latest virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo kernel-desktop-devel-latest nvidia-current-kernel-desktop-latest from updates_testing [root@localhost wilcal]# uname -a Linux localhost 4.9.40-desktop-1.mga6 #1 SMP Fri Jul 28 00:49:58 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.9.40-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox Package virtualbox-5.1.30-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.30-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi dkms-virtualbox Package dkms-virtualbox-5.1.30-1.mga6.noarch is already installed [root@localhost wilcal]# urpmi virtualbox-guest-additions Package virtualbox-guest-additions-5.1.30-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest Package virtualbox-kernel-desktop-latest-5.1.30-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi x11-driver-video-vboxvideo Package x11-driver-video-vboxvideo-5.1.30-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi kernel-desktop-devel-latest Package kernel-desktop-devel-latest-4.9.56-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi dkms-nvidia-current Package dkms-nvidia-current-375.66-3.mga6.nonfree.x86_64 is already installed [wilcal@localhost ~]$ lspci -k 01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1) Subsystem: Gigabyte Technology Co., Ltd Device 3518 Kernel driver in use: nvidia Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current System boots to a working desktop. Common apps work. Previously created M6 i586 Xfce LiveDVD runs as a Vbox client. M6 x86_64 Gnome LiveDVD runs as a Vbox client. M6 x86_64 Plasma LiveDVD, installs and updates as a Vbox client. Test platform: Intel Core i7-2600K Sandy Bridge 3.4GHz GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB RTL8111/8168B PCI Express 1Gbit Ethernet DRAM 16GB (4 x 4GB) Samsung 256GB SSD
CC: (none) => wilcal.int
mga5::x86_64 kernel 4.4.92-desktop-1.mga5 Updated virtualbox. Launched a 64-bit guest running 4.9.56-desktop-1.mga6. Xfce desktop Writing this report in firefox in the vbox. Ran mcc for a tour of the hardware. Looked like CPU #1 on the host was being used by the guest OS. thunar running fine. Downloaded some images from APOD and ran ristretto from the commandline to view them. Used LibreOffice writer to compose a dummy letter. Installed opensshd-server and enabled the sshd service. logged in to the host system and out again. Copied a video file from the host. parole could not play it because of a gstreamer backend error. This is a very bare-bones system. Copied the sudoers file from the host to the guest. Played a short video courtesy of vlc. Mounted a network share and accessed it. Remote login - played an HD video using the remote vlc. It was slow and pixelated - a lot of hoops to jump through. Better performance with a lower resolution video in black and white. Keyboard response was close to instantaneous. This looks fine for 64 bits.
CC: (none) => tarazed25
On real hardware, M5.1, KDE4, 64-bit initial install: kernel-desktop-latest virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo kernel-desktop-devel-latest dkms-nvidia-current [root@localhost wilcal]# uname -a Linux localhost 4.4.92-desktop-1.mga5 #1 SMP Thu Oct 12 20:14:45 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.4.92-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox Package virtualbox-5.1.26-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.26-4.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi dkms-virtualbox Package dkms-virtualbox-5.1.26-1.mga5.noarch is already installed [root@localhost wilcal]# urpmi virtualbox-guest-additions Package virtualbox-guest-additions-5.1.26-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest Package virtualbox-kernel-desktop-latest-5.1.26-4.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi x11-driver-video-vboxvideo Package x11-driver-video-vboxvideo-5.1.26-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi kernel-desktop-devel-latest Package kernel-desktop-devel-latest-4.4.92-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi dkms-nvidia-current Package dkms-nvidia-current-384.59-1.mga5.nonfree.x86_64 is already installed [wilcal@localhost ~]$ lspci -k 01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1) Subsystem: Gigabyte Technology Co., Ltd Device 3518 Kernel driver in use: nvidia Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current M6 i586 Xfce LiveDVD runs as a Vbox client. Boots to a working desktop. Common apps work. Screen sizes are correct. install or check: kernel-desktop-latest virtualbox vboxadditions-kernel-desktop-latest dkms-virtualbox virtualbox-guest-additions virtualbox-kernel-desktop-latest x11-driver-video-vboxvideo kernel-desktop-devel-latest nvidia-current-kernel-desktop-latest from updates_testing [root@localhost wilcal]# uname -a Linux localhost 4.9.40-desktop-1.mga6 #1 SMP Fri Jul 28 00:49:58 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux [root@localhost wilcal]# urpmi kernel-desktop-latest Package kernel-desktop-latest-4.9.40-1.mga6.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox Package virtualbox-5.1.30-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest Package vboxadditions-kernel-desktop-latest-5.1.30-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi dkms-virtualbox Package dkms-virtualbox-5.1.30-1.mga5.noarch is already installed [root@localhost wilcal]# urpmi virtualbox-guest-additions Package virtualbox-guest-additions-5.1.30-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi virtualbox-kernel-desktop-latest Package virtualbox-kernel-desktop-latest-5.1.30-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi x11-driver-video-vboxvideo Package x11-driver-video-vboxvideo-5.1.30-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi kernel-desktop-devel-latest Package kernel-desktop-devel-latest-4.4.92-1.mga5.x86_64 is already installed [root@localhost wilcal]# urpmi dkms-nvidia-current Package dkms-nvidia-current-375.66-3.mga6.nonfree.x86_64 is already installed [wilcal@localhost ~]$ lspci -k 01:00.0 VGA compatible controller: NVIDIA Corporation GF108 [GeForce GT 440] (rev a1) Subsystem: Gigabyte Technology Co., Ltd Device 3518 Kernel driver in use: nvidia Kernel modules: nvidiafb, nouveau, nvidia_drm, nvidia_current System boots to a working desktop. Common apps work. Previously created M6 i586 Xfce LiveDVD runs as a Vbox client. M6 x86_64 Gnome LiveDVD runs as a Vbox client. M6 x86_64 Plasma LiveDVD, installs and updates as a Vbox client. Test platform: Intel Core i7-2600K Sandy Bridge 3.4GHz GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB RTL8111/8168B PCI Express 1Gbit Ethernet DRAM 16GB (4 x 4GB) OCZ 128GB SSD
This update works fine. Testing complete for MGA5 & MGA6, 64-bit Validating this update. Could someone from the sysadmin team push to updates. 32-bit operation not recommended Thanks
Whiteboard: MGA5TOO => MGA5TOO MGA5-64-OK MGA6-64-OKKeywords: (none) => validated_updateCC: (none) => sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2017-0390.html
Resolution: (none) => FIXEDStatus: NEW => RESOLVED