Bug 25454 - Update request: kernel-5.2.16-2.mga7
Summary: Update request: kernel-5.2.16-2.mga7
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK, MGA7-32-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2019-09-19 17:00 CEST by Thomas Backlund
Modified: 2019-09-21 18:06 CEST (History)
5 users (show)

See Also:
Source RPM: kernel
CVE:
Status comment:


Attachments

Description Thomas Backlund 2019-09-19 17:00:16 CEST
SRPMS:
kernel-5.2.16-1.mga7.src.rpm
kernel-userspace-headers-5.2.16-1.mga7.src.rpm
kmod-virtualbox-6.0.10-8.mga7.src.rpm
kmod-xtables-addons-3.3-64.mga7.src.rpm
wireguard-tools-0.0.20190913-1.mga7.src.rpm



i586:
bpftool-5.2.16-1.mga7.i586.rpm
cpupower-5.2.16-1.mga7.i586.rpm
cpupower-devel-5.2.16-1.mga7.i586.rpm
kernel-desktop-5.2.16-1.mga7-1-1.mga7.i586.rpm
kernel-desktop586-5.2.16-1.mga7-1-1.mga7.i586.rpm
kernel-desktop586-devel-5.2.16-1.mga7-1-1.mga7.i586.rpm
kernel-desktop586-devel-latest-5.2.16-1.mga7.i586.rpm
kernel-desktop586-latest-5.2.16-1.mga7.i586.rpm
kernel-desktop-devel-5.2.16-1.mga7-1-1.mga7.i586.rpm
kernel-desktop-devel-latest-5.2.16-1.mga7.i586.rpm
kernel-desktop-latest-5.2.16-1.mga7.i586.rpm
kernel-doc-5.2.16-1.mga7.noarch.rpm
kernel-server-5.2.16-1.mga7-1-1.mga7.i586.rpm
kernel-server-devel-5.2.16-1.mga7-1-1.mga7.i586.rpm
kernel-server-devel-latest-5.2.16-1.mga7.i586.rpm
kernel-server-latest-5.2.16-1.mga7.i586.rpm
kernel-source-5.2.16-1.mga7-1-1.mga7.noarch.rpm
kernel-source-latest-5.2.16-1.mga7.noarch.rpm
kernel-userspace-headers-5.2.16-1.mga7.i586.rpm
libbpf0-5.2.16-1.mga7.i586.rpm
libbpf-devel-5.2.16-1.mga7.i586.rpm
perf-5.2.16-1.mga7.i586.rpm

virtualbox-kernel-5.2.16-desktop-1.mga7-6.0.10-8.mga7.i586.rpm
virtualbox-kernel-5.2.16-desktop586-1.mga7-6.0.10-8.mga7.i586.rpm
virtualbox-kernel-5.2.16-server-1.mga7-6.0.10-8.mga7.i586.rpm
virtualbox-kernel-desktop586-latest-6.0.10-8.mga7.i586.rpm
virtualbox-kernel-desktop-latest-6.0.10-8.mga7.i586.rpm
virtualbox-kernel-server-latest-6.0.10-8.mga7.i586.rpm

xtables-addons-kernel-5.2.16-desktop-1.mga7-3.3-64.mga7.i586.rpm
xtables-addons-kernel-5.2.16-desktop586-1.mga7-3.3-64.mga7.i586.rpm
xtables-addons-kernel-5.2.16-server-1.mga7-3.3-64.mga7.i586.rpm
xtables-addons-kernel-desktop586-latest-3.3-64.mga7.i586.rpm
xtables-addons-kernel-desktop-latest-3.3-64.mga7.i586.rpm
xtables-addons-kernel-server-latest-3.3-64.mga7.i586.rpm

wireguard-tools-0.0.20190913-1.mga7.i586.rpm



x86_64:
bpftool-5.2.16-1.mga7.x86_64.rpm
cpupower-5.2.16-1.mga7.x86_64.rpm
cpupower-devel-5.2.16-1.mga7.x86_64.rpm
kernel-desktop-5.2.16-1.mga7-1-1.mga7.x86_64.rpm
kernel-desktop-devel-5.2.16-1.mga7-1-1.mga7.x86_64.rpm
kernel-desktop-devel-latest-5.2.16-1.mga7.x86_64.rpm
kernel-desktop-latest-5.2.16-1.mga7.x86_64.rpm
kernel-doc-5.2.16-1.mga7.noarch.rpm
kernel-server-5.2.16-1.mga7-1-1.mga7.x86_64.rpm
kernel-server-devel-5.2.16-1.mga7-1-1.mga7.x86_64.rpm
kernel-server-devel-latest-5.2.16-1.mga7.x86_64.rpm
kernel-server-latest-5.2.16-1.mga7.x86_64.rpm
kernel-source-5.2.16-1.mga7-1-1.mga7.noarch.rpm
kernel-source-latest-5.2.16-1.mga7.noarch.rpm
kernel-userspace-headers-5.2.16-1.mga7.x86_64.rpm
lib64bpf0-5.2.16-1.mga7.x86_64.rpm
lib64bpf-devel-5.2.16-1.mga7.x86_64.rpm
perf-5.2.16-1.mga7.x86_64.rpm

virtualbox-kernel-5.2.16-desktop-1.mga7-6.0.10-8.mga7.x86_64.rpm
virtualbox-kernel-5.2.16-server-1.mga7-6.0.10-8.mga7.x86_64.rpm
virtualbox-kernel-desktop-latest-6.0.10-8.mga7.x86_64.rpm
virtualbox-kernel-server-latest-6.0.10-8.mga7.x86_64.rpm

xtables-addons-kernel-5.2.16-desktop-1.mga7-3.3-64.mga7.x86_64.rpm
xtables-addons-kernel-5.2.16-server-1.mga7-3.3-64.mga7.x86_64.rpm
xtables-addons-kernel-desktop-latest-3.3-64.mga7.x86_64.rpm
xtables-addons-kernel-server-latest-3.3-64.mga7.x86_64.rpm

wireguard-tools-0.0.20190913-1.mga7.x86_64.rpm
Comment 1 Brian Rockwell 2019-09-19 21:38:21 CEST
Physical hardware AMD X3, Nvidia GT730 (Nvidia 390) running GNOME

The following 5 packages are going to be installed:

- cpupower-5.2.16-1.mga7.x86_64
- kernel-desktop-5.2.16-1.mga7-1-1.mga7.x86_64
- kernel-desktop-devel-5.2.16-1.mga7-1-1.mga7.x86_64
- kernel-desktop-devel-latest-5.2.16-1.mga7.x86_64
- kernel-desktop-latest-5.2.16-1.mga7.x86_64

---

rebooted

# uname -a
Linux linux.local 5.2.16-desktop-1.mga7 #1 SMP Thu Sep 19 08:36:49 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux

# lsmod | grep nvidia
nvidia_drm             49152  2
nvidia_modeset       1056768  14 nvidia_drm
nvidia              14704640  597 nvidia_modeset
ipmi_msghandler        61440  2 ipmi_devintf,nvidia
drm_kms_helper        221184  1 nvidia_drm
drm                   516096  6 drm_kms_helper,nvidia_drm,ttm

Things worked fine

---

Went back and applied microcode-0.20190918 and rebooted (note this is AMD)

--- 

system is working fine.

CC: (none) => brtians1

Comment 2 William Kenney 2019-09-19 23:59:12 CEST
In a Vbox client, M7.1, Gnome, 32-bit

Testing: kernel-desktop-latest cpupower

[root@localhost wilcal]# uname -a
Linux localhost 5.2.13-desktop586-2.mga7 #1 SMP Sun Sep 8 10:47:52 UTC 2019 i686 i686 i386 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop586-latest
Package kernel-desktop586-latest-5.2.13-2.mga7.i586 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-5.2.13-2.mga7.i586 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

Install kernel-desktop586-latest cpupower from updates testing

The following 2 packages are going to be installed:

- cpupower-5.2.15-1.mga7.i586
- kernel-desktop586-5.2.15-1.mga7-1-1.mga7.i586

Reboot system.

[root@localhost wilcal]# uname -a
Linux localhost 5.2.15-desktop586-1.mga7 #1 SMP Mon Sep 16 21:16:43 UTC 2019 i686 i686 i386 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop586-latest
Package kernel-desktop586-latest-5.2.15-1.mga7.i586 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-5.2.15-1.mga7.i586 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

CC: (none) => wilcal.int

Comment 3 William Kenney 2019-09-19 23:59:36 CEST
In a Vbox client, M7.1, Plasma, 64-bit

Testing: kernel-desktop-latest cpupower

[root@localhost wilcal]# uname -a
Linux localhost 5.2.13-desktop-2.mga7 #1 SMP Sun Sep 8 10:54:20 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-5.2.13-2.mga7.x86_64 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-5.2.13-2.mga7.x86_64 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

Install kernel-desktop-latest cpupower from updates testing

The following 3 packages are going to be installed:

- cpupower-5.2.15-1.mga7.x86_64
- kernel-desktop-5.2.15-1.mga7-1-1.mga7.x86_64
- kernel-desktop-latest-5.2.15-1.mga7.x86_64

Reboot system.

[root@localhost wilcal]# uname -a
Linux localhost 5.2.15-desktop-1.mga7 #1 SMP Mon Sep 16 21:03:44 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-5.2.15-1.mga7.x86_64 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-5.2.15-1.mga7.x86_64 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.
Comment 4 Ben McMonagle 2019-09-20 09:24:28 CEST
Mga6 on real 32bit hardware desktop(lxde DE system)

$ uname -r
5.1.14-desktop-1.mga7


$ lscpu
Architecture:          i686
CPU op-mode(s):        32-bit

AMD Athlon(tm) XP 2400+

Flags:                 fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge
                       mca cmov pat pse36 mmx fxsr sse syscall mmxext 3dnowext 
                       3dnow cpuid 3dnowprefetch vmmcall

To satisfy dependencies, the following packages are going to be installed:
  Package                        Version      Release       Arch    
(medium "Core Updates Testing (distrib5)")
  cpupower                       5.2.16       1.mga7        i586    
  kernel-desktop-5.2.16-1.mga7   1            1.mga7        i586    
  kernel-desktop-latest          5.2.16       1.mga7        i586    
  wireguard-tools                0.0.20190913 1.mga7        i586    
60MB of additional disk space will be used.
54MB of packages will be retrieved.
Proceed with the installation of the 4 packages? (Y/n) y

Creating: target|kernel|dracut args|basicmodules 
remove-boot-splash: Format of /boot/initrd-5.2.16-desktop-1.mga7.img not recognized
You should restart your computer for kernel-desktop-5.2.16-1.mga7

(reboot)

$ uname -r
5.2.16-desktop-1.mga7

firefox -ok
usb stick detected and pop-up - ok
playback .mkv sound abd video -ok

CC: (none) => westel

Comment 5 Thomas Backlund 2019-09-20 15:33:28 CEST
Sorry, missed 4 security fixes, of wich one is critical enough for a rebuild, so a -2.mga6 is building

Keywords: (none) => feedback

Comment 6 Thomas Backlund 2019-09-20 22:59:50 CEST
So the security fixes I added is for kvm and the mvifiex driver, nothing else
so as long as it still installs and boots properly, it should be all good to go

:)


SRPMS:
kernel-5.2.16-2.mga7.src.rpm
kernel-userspace-headers-5.2.16-2.mga7.src.rpm
kmod-virtualbox-6.0.10-10.mga7.src.rpm
kmod-xtables-addons-3.3-66.mga7.src.rpm
wireguard-tools-0.0.20190913-1.mga7.src.rpm



i586:
bpftool-5.2.16-2.mga7.i586.rpm
cpupower-5.2.16-2.mga7.i586.rpm
cpupower-devel-5.2.16-2.mga7.i586.rpm
kernel-desktop-5.2.16-2.mga7-1-1.mga7.i586.rpm
kernel-desktop586-5.2.16-2.mga7-1-1.mga7.i586.rpm
kernel-desktop586-devel-5.2.16-2.mga7-1-1.mga7.i586.rpm
kernel-desktop586-devel-latest-5.2.16-2.mga7.i586.rpm
kernel-desktop586-latest-5.2.16-2.mga7.i586.rpm
kernel-desktop-devel-5.2.16-2.mga7-1-1.mga7.i586.rpm
kernel-desktop-devel-latest-5.2.16-2.mga7.i586.rpm
kernel-desktop-latest-5.2.16-2.mga7.i586.rpm
kernel-doc-5.2.16-2.mga7.noarch.rpm
kernel-server-5.2.16-2.mga7-1-1.mga7.i586.rpm
kernel-server-devel-5.2.16-2.mga7-1-1.mga7.i586.rpm
kernel-server-devel-latest-5.2.16-2.mga7.i586.rpm
kernel-server-latest-5.2.16-2.mga7.i586.rpm
kernel-source-5.2.16-2.mga7-1-1.mga7.noarch.rpm
kernel-source-latest-5.2.16-2.mga7.noarch.rpm
kernel-userspace-headers-5.2.16-2.mga7.i586.rpm
libbpf0-5.2.16-2.mga7.i586.rpm
libbpf-devel-5.2.16-2.mga7.i586.rpm
perf-5.2.16-2.mga7.i586.rpm

virtualbox-kernel-5.2.16-desktop-2.mga7-6.0.10-10.mga7.i586.rpm
virtualbox-kernel-5.2.16-desktop586-2.mga7-6.0.10-10.mga7.i586.rpm
virtualbox-kernel-5.2.16-server-2.mga7-6.0.10-10.mga7.i586.rpm
virtualbox-kernel-desktop586-latest-6.0.10-8.mga7.i586.rpm
virtualbox-kernel-desktop-latest-6.0.10-10.mga7.i586.rpm
virtualbox-kernel-server-latest-6.0.10-10.mga7.i586.rpm

xtables-addons-kernel-5.2.16-desktop-2.mga7-3.3-66.mga7.i586.rpm
xtables-addons-kernel-5.2.16-desktop586-2.mga7-3.3-66.mga7.i586.rpm
xtables-addons-kernel-5.2.16-server-2.mga7-3.3-66.mga7.i586.rpm
xtables-addons-kernel-desktop586-latest-3.3-66.mga7.i586.rpm
xtables-addons-kernel-desktop-latest-3.3-66.mga7.i586.rpm
xtables-addons-kernel-server-latest-3.3-66.mga7.i586.rpm

wireguard-tools-0.0.20190913-1.mga7.i586.rpm



x86_64:
bpftool-5.2.16-2.mga7.x86_64.rpm
cpupower-5.2.16-2.mga7.x86_64.rpm
cpupower-devel-5.2.16-2.mga7.x86_64.rpm
kernel-desktop-5.2.16-2.mga7-1-1.mga7.x86_64.rpm
kernel-desktop-devel-5.2.16-2.mga7-1-1.mga7.x86_64.rpm
kernel-desktop-devel-latest-5.2.16-2.mga7.x86_64.rpm
kernel-desktop-latest-5.2.16-2.mga7.x86_64.rpm
kernel-doc-5.2.16-2.mga7.noarch.rpm
kernel-server-5.2.16-2.mga7-1-1.mga7.x86_64.rpm
kernel-server-devel-5.2.16-2.mga7-1-1.mga7.x86_64.rpm
kernel-server-devel-latest-5.2.16-2.mga7.x86_64.rpm
kernel-server-latest-5.2.16-2.mga7.x86_64.rpm
kernel-source-5.2.16-2.mga7-1-1.mga7.noarch.rpm
kernel-source-latest-5.2.16-2.mga7.noarch.rpm
kernel-userspace-headers-5.2.16-2.mga7.x86_64.rpm
lib64bpf0-5.2.16-2.mga7.x86_64.rpm
lib64bpf-devel-5.2.16-2.mga7.x86_64.rpm
perf-5.2.16-2.mga7.x86_64.rpm

virtualbox-kernel-5.2.16-desktop-2.mga7-6.0.10-10.mga7.x86_64.rpm
virtualbox-kernel-5.2.16-server-2.mga7-6.0.10-10.mga7.x86_64.rpm
virtualbox-kernel-desktop-latest-6.0.10-10.mga7.x86_64.rpm
virtualbox-kernel-server-latest-6.0.10-10.mga7.x86_64.rpm

xtables-addons-kernel-5.2.16-desktop-2.mga7-3.3-66.mga7.x86_64.rpm
xtables-addons-kernel-5.2.16-server-2.mga7-3.3-66.mga7.x86_64.rpm
xtables-addons-kernel-desktop-latest-3.3-66.mga7.x86_64.rpm
xtables-addons-kernel-server-latest-3.3-66.mga7.x86_64.rpm

wireguard-tools-0.0.20190913-1.mga7.x86_64.rpm

Summary: Update request: kernel-5.2.16-1.mga7 => Update request: kernel-5.2.16-2.mga7
Keywords: feedback => (none)

Comment 7 Herman Viaene 2019-09-21 10:31:36 CEST
MGA7-64 Plasma n Lenovo B50
No installation issues
No problems with wifi, odt, ods, odb, mpg, jpeg, surf on newspaper site, wav files. OK for me.

CC: (none) => herman.viaene

Comment 8 Thomas Backlund 2019-09-21 15:40:05 CEST
Advisory, added to svn:

type: security
subject: Updated kernel packages fix security vulnerabilities
CVE:
 - CVE-2019-14814
 - CVE-2019-14815
 - CVE-2019-14816
 - CVE-2019-14821
 - CVE-2019-14835
src:
  7:
   core:
     - kernel-5.2.16-2.mga7
     - kernel-userspace-headers-5.2.16-2.mga7
     - kmod-virtualbox-6.0.10-10.mga7
     - kmod-xtables-addons-3.3-66.mga7
     - wireguard-tools-0.0.20190913-1.mga7
description: |
  This kernel update is based on the upstream 5.2.16 and fixes atleast
  the following security issues:

  There is heap-based buffer overflow in the marvell wifi chip driver that
  allows local users to cause a denial of service(system crash) or possibly
  execute arbitrary code (CVE-2019-14814, CVE-2019-14815, CVE-2019-14816).

  An out-of-bounds access issue was found in the way Linux kernel's KVM
  hypervisor implements the Coalesced MMIO write operation. It operates on
  an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write
  indices 'ring->first' and 'ring->last' value could be supplied by a host
  user-space process. An unprivileged host user or process with access to
  '/dev/kvm' device could use this flaw to crash the host kernel, resulting
  in a denial of service or potentially escalating privileges on the system
  (CVE-2019-14821).

  A buffer overflow flaw was found in the way Linux kernel's vhost
  functionality that translates virtqueue buffers to IOVs, logged the buffer
  descriptors during migration. A privileged guest user able to pass
  descriptors with invalid length to the host when migration is underway,
  could use this flaw to increase their privileges on the host
  (CVE-2019-14835).

  WireGuard has been updated to 0.0.20190913.

  For other uptstream fixes in this update, see the referenced changelogs.
references:
 - https://bugs.mageia.org/show_bug.cgi?id=25454
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-5.2.14
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-5.2.15
 - https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-5.2.16

Keywords: (none) => advisory

Comment 9 William Kenney 2019-09-21 16:33:34 CEST
In a Vbox client, M7.1, Gnome, 32-bit

Testing: kernel-desktop-latest cpupower

[root@localhost wilcal]# uname -a
Linux localhost 5.2.13-desktop586-2.mga7 #1 SMP Sun Sep 8 10:47:52 UTC 2019 i686 i686 i386 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop586-latest
Package kernel-desktop586-latest-5.2.13-2.mga7.i586 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-5.2.13-2.mga7.i586 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

Install kernel-desktop586-latest cpupower from updates testing

TThe following 2 packages are going to be installed:

- cpupower-5.2.16-2.mga7.i586
- kernel-desktop586-5.2.16-2.mga7-1-1.mga7.i586

Reboot system.

[root@localhost wilcal]# uname -a
Linux localhost 5.2.16-desktop586-2.mga7 #1 SMP Fri Sep 20 14:05:38 UTC 2019 i686 i686 i386 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop586-latest
Package kernel-desktop586-latest-5.2.16-2.mga7.i586 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-5.2.16-2.mga7.i586 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.
Comment 10 William Kenney 2019-09-21 16:34:05 CEST
In a Vbox client, M7.1, Plasma, 64-bit

Testing: kernel-desktop-latest cpupower

[root@localhost wilcal]# uname -a
Linux localhost 5.2.13-desktop-2.mga7 #1 SMP Sun Sep 8 10:54:20 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-5.2.13-2.mga7.x86_64 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-5.2.13-2.mga7.x86_64 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

Install kernel-desktop-latest cpupower from updates testing

The following 3 packages are going to be installed:

- cpupower-5.2.16-2.mga7.x86_64
- kernel-desktop-5.2.16-2.mga7-1-1.mga7.x86_64
- kernel-desktop-latest-5.2.16-2.mga7.x86_64

Reboot system.

[root@localhost wilcal]# uname -a
Linux localhost 5.2.16-desktop-2.mga7 #1 SMP Fri Sep 20 14:06:22 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
[root@localhost wilcal]# urpmi kernel-desktop-latest
Package kernel-desktop-latest-5.2.16-2.mga7.x86_64 is already installed
[root@localhost wilcal]# urpmi cpupower
Package cpupower-5.2.16-2.mga7.x86_64 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.
Thomas Backlund 2019-09-21 17:15:35 CEST

Keywords: (none) => validated_update
Whiteboard: (none) => MGA7-64-OK, MGA7-32-OK
CC: (none) => sysadmin-bugs

Comment 11 Mageia Robot 2019-09-21 18:06:40 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2019-0288.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.