Bug 25014 - Update request: kernel-4.14.131-1.mga6
Summary: Update request: kernel-4.14.131-1.mga6
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA6-32-OK MGA6-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2019-06-27 17:35 CEST by Thomas Backlund
Modified: 2019-07-02 19:06 CEST (History)
6 users (show)

See Also:
Source RPM: kernel
CVE:
Status comment:


Attachments

Description Thomas Backlund 2019-06-27 17:35:58 CEST
Fixup for tcp stack security fixes in last update (4.14.127) that broke atleast steam platform.

Also some block level fixes for a potential silent data corruption using O_DIRECT setups...

And other upstream fixes...

SRPMS:
kernel-4.14.131-1.mga6.src.rpm
kernel-userspace-headers-4.14.131-1.mga6.src.rpm

kmod-vboxadditions-6.0.8-5.mga6.src.rpm
kmod-virtualbox-6.0.8-5.mga6.src.rpm
kmod-xtables-addons-2.13-89.mga6.src.rpm


i586:
cpupower-4.14.131-1.mga6.i586.rpm
cpupower-devel-4.14.131-1.mga6.i586.rpm
kernel-desktop-4.14.131-1.mga6-1-1.mga6.i586.rpm
kernel-desktop586-4.14.131-1.mga6-1-1.mga6.i586.rpm
kernel-desktop586-devel-4.14.131-1.mga6-1-1.mga6.i586.rpm
kernel-desktop586-devel-latest-4.14.131-1.mga6.i586.rpm
kernel-desktop586-latest-4.14.131-1.mga6.i586.rpm
kernel-desktop-devel-4.14.131-1.mga6-1-1.mga6.i586.rpm
kernel-desktop-devel-latest-4.14.131-1.mga6.i586.rpm
kernel-desktop-latest-4.14.131-1.mga6.i586.rpm
kernel-doc-4.14.131-1.mga6.noarch.rpm
kernel-server-4.14.131-1.mga6-1-1.mga6.i586.rpm
kernel-server-devel-4.14.131-1.mga6-1-1.mga6.i586.rpm
kernel-server-devel-latest-4.14.131-1.mga6.i586.rpm
kernel-server-latest-4.14.131-1.mga6.i586.rpm
kernel-source-4.14.131-1.mga6-1-1.mga6.noarch.rpm
kernel-source-latest-4.14.131-1.mga6.noarch.rpm
kernel-userspace-headers-4.14.131-1.mga6.i586.rpm
perf-4.14.131-1.mga6.i586.rpm

vboxadditions-kernel-4.14.131-desktop-1.mga6-6.0.8-5.mga6.i586.rpm
vboxadditions-kernel-4.14.131-desktop586-1.mga6-6.0.8-5.mga6.i586.rpm
vboxadditions-kernel-4.14.131-server-1.mga6-6.0.8-5.mga6.i586.rpm
vboxadditions-kernel-desktop586-latest-6.0.8-5.mga6.i586.rpm
vboxadditions-kernel-desktop-latest-6.0.8-5.mga6.i586.rpm
vboxadditions-kernel-server-latest-6.0.8-5.mga6.i586.rpm

virtualbox-kernel-4.14.131-desktop-1.mga6-6.0.8-5.mga6.i586.rpm
virtualbox-kernel-4.14.131-desktop586-1.mga6-6.0.8-5.mga6.i586.rpm
virtualbox-kernel-4.14.131-server-1.mga6-6.0.8-5.mga6.i586.rpm
virtualbox-kernel-desktop586-latest-6.0.8-5.mga6.i586.rpm
virtualbox-kernel-desktop-latest-6.0.8-5.mga6.i586.rpm
virtualbox-kernel-server-latest-6.0.8-5.mga6.i586.rpm

xtables-addons-kernel-4.14.131-desktop-1.mga6-2.13-89.mga6.i586.rpm
xtables-addons-kernel-4.14.131-desktop586-1.mga6-2.13-89.mga6.i586.rpm
xtables-addons-kernel-4.14.131-server-1.mga6-2.13-89.mga6.i586.rpm
xtables-addons-kernel-desktop586-latest-2.13-89.mga6.i586.rpm
xtables-addons-kernel-desktop-latest-2.13-89.mga6.i586.rpm
xtables-addons-kernel-server-latest-2.13-89.mga6.i586.rpm


x86_64:
cpupower-4.14.131-1.mga6.x86_64.rpm
cpupower-devel-4.14.131-1.mga6.x86_64.rpm
kernel-desktop-4.14.131-1.mga6-1-1.mga6.x86_64.rpm
kernel-desktop-devel-4.14.131-1.mga6-1-1.mga6.x86_64.rpm
kernel-desktop-devel-latest-4.14.131-1.mga6.x86_64.rpm
kernel-desktop-latest-4.14.131-1.mga6.x86_64.rpm
kernel-doc-4.14.131-1.mga6.noarch.rpm
kernel-server-4.14.131-1.mga6-1-1.mga6.x86_64.rpm
kernel-server-devel-4.14.131-1.mga6-1-1.mga6.x86_64.rpm
kernel-server-devel-latest-4.14.131-1.mga6.x86_64.rpm
kernel-server-latest-4.14.131-1.mga6.x86_64.rpm
kernel-source-4.14.131-1.mga6-1-1.mga6.noarch.rpm
kernel-source-latest-4.14.131-1.mga6.noarch.rpm
kernel-userspace-headers-4.14.131-1.mga6.x86_64.rpm
perf-4.14.131-1.mga6.x86_64.rpm

vboxadditions-kernel-4.14.131-desktop-1.mga6-6.0.8-5.mga6.x86_64.rpm
vboxadditions-kernel-4.14.131-server-1.mga6-6.0.8-5.mga6.x86_64.rpm
vboxadditions-kernel-desktop-latest-6.0.8-5.mga6.x86_64.rpm
vboxadditions-kernel-server-latest-6.0.8-5.mga6.x86_64.rpm

virtualbox-kernel-4.14.131-desktop-1.mga6-6.0.8-5.mga6.x86_64.rpm
virtualbox-kernel-4.14.131-server-1.mga6-6.0.8-5.mga6.x86_64.rpm
virtualbox-kernel-desktop-latest-6.0.8-5.mga6.x86_64.rpm
virtualbox-kernel-server-latest-6.0.8-5.mga6.x86_64.rpm

xtables-addons-kernel-4.14.131-desktop-1.mga6-2.13-89.mga6.x86_64.rpm
xtables-addons-kernel-4.14.131-server-1.mga6-2.13-89.mga6.x86_64.rpm
xtables-addons-kernel-desktop-latest-2.13-89.mga6.x86_64.rpm
xtables-addons-kernel-server-latest-2.13-89.mga6.x86_64.rpm
Thomas Backlund 2019-06-27 18:02:58 CEST

QA Contact: (none) => security
Component: RPM Packages => Security

Comment 1 Thomas Backlund 2019-06-27 20:51:09 CEST
 x86_64 kernel-server-4.14.131-1.mga6 is now running on Mageia infra
Comment 2 Brian Rockwell 2019-06-28 00:25:19 CEST
AMD x2-3800, running 32bit.  Mate.  Legancy nvidia running nouveau (physical hardware.

- cpupower-4.14.131-1.mga6.i586
- cpupower-devel-4.14.131-1.mga6.i586
- kernel-desktop-4.14.131-1.mga6-1-1.mga6.i586
- kernel-desktop-latest-4.14.131-1.mga6.i586
- kernel-doc-4.14.131-1.mga6.noarch
- rpmdrake-6.27.1-1.mga6.noarch

Rebooted after install

$ uname -am
Linux localhost 4.14.131-desktop-1.mga6 #1 SMP Thu Jun 27 12:34:46 UTC 2019 i686 i686 i686 GNU/Linux


samba server is working, browser is working.  No issues detected so far.

CC: (none) => brtians1

Comment 3 Brian Rockwell 2019-06-28 01:06:58 CEST
AMD Athlon II X3 450 Processor (classic bios), Nvidia GeForce GT 730

$ uname -a
Linux localhost 4.14.131-desktop-1.mga6 #1 SMP Thu Jun 27 11:19:36 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux


Nvidia driver is active and working.

System is functioning properly.
Comment 4 Morgan Leijström 2019-06-28 01:48:38 CEST
OK mga6-64, i7, Nvidia GPU and driver, Plasma

Been using it several hours; Thunderbird, LibreOffice6, video+audio in Firefox, VirtualBox running MSW7 incl USB2 flash stick and windowsupdate.  CUDA and OpenCL recognized by BOINC.

Smooth installation and reboot.
This system also updates all installed to testing.
$ uname -a
Linux svarten 4.14.131-desktop-1.mga6 #1 SMP Thu Jun 27 11:19:36 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux

Hardware: i7-2600K, Nvidia GTX760 (GK104) using proprietary driver GeForce 420 and later, with CUDA & OpenCL detected OK in BOINC (but not used), / & /home & swap in LVM on LUKS on SSD

CC: (none) => fri

Comment 5 James Kerr 2019-06-28 16:27:31 CEST
on mga6-64  kernel-desktop  plasma

packages installed cleanly:
- cpupower-4.14.131-1.mga6.x86_64
- kernel-desktop-4.14.131-1.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-4.14.131-1.mga6-1-1.mga6.x86_64
- kernel-desktop-devel-latest-4.14.131-1.mga6.x86_64
- kernel-desktop-latest-4.14.131-1.mga6.x86_64
- kernel-userspace-headers-4.14.131-1.mga6.x86_64
- virtualbox-kernel-4.14.131-desktop-1.mga6-6.0.8-5.mga6.x86_64
- virtualbox-kernel-desktop-latest-6.0.8-5.mga6.x86_64

system rebooted normally:
$ uname -r
4.14.131-desktop-1.mga6
# dkms status
virtualbox, 6.0.8-1.mga6, 4.14.131-desktop-1.mga6, x86_64: installed 
virtualbox, 6.0.8-1.mga6, 4.14.131-desktop-1.mga6, x86_64: installed-binary from 4.14.131-desktop-1.mga6

vbox and clients launched normally

no regressions noted

looks OK for mga6-64 on this system:

Machine:   Device: desktop System: Dell product: Precision Tower 3620
           Mobo: Dell model: 09WH54 v: A00 UEFI [Legacy]: Dell v: 2.12.0
CPU:       Quad core Intel Core i7-6700 (-HT-MCP-)
Graphics:  Card: Intel HD Graphics 530

(Also installed kernel-desktop-4.14.131 in mga6-32 vbox client - no regressions noted)

CC: (none) => jim

Comment 6 Herman Viaene 2019-06-29 16:21:56 CEST
MGA6-32 MATE on IBM Thinkpad R50e
Installation: this is the first time I install kernel-devel on this laptop, and this draws in a lot of dependencies. I didn't look close enough what it all was, and it included kernel-develop-latest-4.18.20, so selecting kernel-develop-latest-4.14.131 was not allowed because of conflict with the 4.18 version. This laptop had a complete reinstall of MGA6 just a week ago, so kernel 4.18 hasn't been even in its neighbourhood. Manually removing this offending version and selecting the right one was all that was needed, but it's a PITA.
Once all installed and rebooted, using firefox, opening doc, ods, pdf, jpg and some more, accessing remote NFS shares, all work OK. No other obvious problems seen.

CC: (none) => herman.viaene

Comment 7 William Kenney 2019-07-01 00:08:50 CEST
In a Vbox client, M6.1, Plasma, 32-bit

Testing: kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower

[root@localhost wilcal]# uname -a
Linux localhost 4.14.127-desktop-1.mga6 #1 SMP Mon Jun 17 22:20:44 UTC 2019 i686 i686 i686 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.127-1.mga6.i586 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-6.0.8-4.mga6.i586 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.127-1.mga6.i586 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

Install kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower from updates testing

The following 5 packages are going to be installed:

- cpupower-4.14.131-1.mga6.i586
- kernel-desktop-4.14.131-1.mga6-1-1.mga6.i586
- kernel-desktop-latest-4.14.131-1.mga6.i586
- vboxadditions-kernel-4.14.131-desktop-1.mga6-6.0.8-5.mga6.i586
- vboxadditions-kernel-desktop-latest-6.0.8-5.mga6.i586

Reboot system.

[root@localhost wilcal]# uname -a
Linux localhost 4.14.131-desktop-1.mga6 #1 SMP Thu Jun 27 12:34:46 UTC 2019 i686 i686 i686 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.131-1.mga6.i586 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-6.0.8-5.mga6.i586 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.131-1.mga6.i586 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

CC: (none) => wilcal.int

Comment 8 William Kenney 2019-07-01 00:09:14 CEST
In a Vbox client, M6.1, Plasma, 64-bit

Testing: kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower

[root@localhost wilcal]# uname -a
Linux localhost 4.14.127-desktop-1.mga6 #1 SMP Mon Jun 17 21:30:07 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.127-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-6.0.8-4.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.127-1.mga6.x86_64 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

Install kernel-desktop-latest vboxadditions-kernel-desktop-latest cpupower from updates testing

The following 5 packages are going to be installed:

- cpupower-4.14.131-1.mga6.x86_64
- kernel-desktop-4.14.131-1.mga6-1-1.mga6.x86_64
- kernel-desktop-latest-4.14.131-1.mga6.x86_64
- vboxadditions-kernel-4.14.131-desktop-1.mga6-6.0.8-5.mga6.x86_64
- vboxadditions-kernel-desktop-latest-6.0.8-5.mga6.x86_64

Reboot system.

[root@localhost wilcal]# uname -a
Linux localhost 4.14.131-desktop-1.mga6 #1 SMP Thu Jun 27 11:19:36 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-4.14.131-1.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi vboxadditions-kernel-desktop-latest
Package vboxadditions-kernel-desktop-latest-6.0.8-5.mga6.x86_64 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-4.14.131-1.mga6.x86_64 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.
Comment 9 Thomas Backlund 2019-07-02 18:23:36 CEST
Validating with advisory:

type: bugfix
subject: Updated kernel packages fixes bugs and a tcp regression
src:
  6:
   core:
     - kernel-4.14.131-1.mga6
     - kernel-userspace-headers-4.14.131-1.mga6
     - kmod-vboxadditions-6.0.8-5.mga6
     - kmod-virtualbox-6.0.8-5.mga6
     - kmod-xtables-addons-2.13-89.mga6
description:
  This kernel update is based on the upstream 4.14.131 and fixes various
  bugs like use-after-free, null-pointer dereferences and so on.

  It also fixes a regression in the network tcp stack caused by the secirity
  fixes added in the MGASA-2019-0195 update, causing applications like steam
  to stop working.

  For other uptstream fixes in this update, see the referenced changelogs.
references:
 - https://bugs.mageia.org/show_bug.cgi?id=25014
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.128
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.129
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.130
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.131

Keywords: (none) => advisory, validated_update
Whiteboard: (none) => MGA6-32-OK MGA6-64-OK
CC: (none) => sysadmin-bugs

Comment 10 Mageia Robot 2019-07-02 19:06:50 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGAA-2019-0045.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.