Bug 28828 - Update request: virtualbox 6.1.20
Summary: Update request: virtualbox 6.1.20
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7TOO MGA8-64-OK MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks: 27362 27433 27936 28734
  Show dependency treegraph
 
Reported: 2021-04-22 19:37 CEST by Thomas Backlund
Modified: 2021-04-24 00:55 CEST (History)
5 users (show)

See Also:
Source RPM: virtualbox
CVE:
Status comment:


Attachments

Description Thomas Backlund 2021-04-22 19:37:08 CEST
Security and bugfixes... advisory will follow...

SRPMS:
virtualbox-6.1.20-1.1.mga8.src.rpm
kmod-virtualbox-6.1.20-1.1.mga8.src.rpm


i586:
virtualbox-6.1.20-1.1.mga8.i586.rpm
virtualbox-guest-additions-6.1.20-1.1.mga8.i586.rpm


x86_64:
dkms-virtualbox-6.1.20-1.1.mga8.x86_64.rpm
python-virtualbox-6.1.20-1.1.mga8.x86_64.rpm
virtualbox-6.1.20-1.1.mga8.x86_64.rpm
virtualbox-devel-6.1.20-1.1.mga8.x86_64.rpm
virtualbox-guest-additions-6.1.20-1.1.mga8.x86_64.rpm

virtualbox-kernel-5.10.30-desktop-1.mga8-6.1.20-1.1.mga8.x86_64.rpm
virtualbox-kernel-5.10.30-server-1.mga8-6.1.20-1.1.mga8.x86_64.rpm
virtualbox-kernel-desktop-latest-6.1.20-1.1.mga8.x86_64.rpm
virtualbox-kernel-server-latest-6.1.20-1.1.mga8.x86_64.rpm
Comment 1 Thomas Backlund 2021-04-22 19:40:47 CEST
Mga7 rpms:

SRPMS:
virtualbox-6.1.20-1.mga7.src.rpm
kmod-virtualbox-6.1.20-1.mga7.src.rpm


i586:
virtualbox-6.1.20-1.mga7.i586.rpm
virtualbox-guest-additions-6.1.20-1.mga7.i586.rpm


x86_64:
dkms-virtualbox-6.1.20-1.mga7.x86_64.rpm
python-virtualbox-6.1.20-1.mga7.x86_64.rpm
virtualbox-6.1.20-1.mga7.x86_64.rpm
virtualbox-devel-6.1.20-1.mga7.x86_64.rpm
virtualbox-guest-additions-6.1.20-1.mga7.x86_64.rpm

virtualbox-kernel-5.10.30-desktop-1.mga7-6.1.20-1.mga7.x86_64.rpm
virtualbox-kernel-5.10.30-server-1.mga7-6.1.20-1.mga7.x86_64.rpm
virtualbox-kernel-desktop-latest-6.1.20-1.mga7.x86_64.rpm
virtualbox-kernel-server-latest-6.1.20-1.mga7.x86_64.rpm

Whiteboard: (none) => MGA7TOO

Comment 2 Thomas Backlund 2021-04-22 19:45:45 CEST
this update also contains fixes for bug 27362, bug 27936, bug 28734

Blocks: (none) => 27362, 27936, 28734

Comment 3 Morgan Leijström 2021-04-23 00:50:48 CEST
OK: mga8-64 Plasma, nvidia-curent, kernel 5.10.30-desktop-1.mga8

- dkms-virtualbox-6.1.20-1.1.mga8.x86_64
- virtualbox-6.1.20-1.1.mga8.x86_64
- virtualbox-kernel-5.10.30-desktop-1.mga8-6.1.20-1.1.mga8.x86_64
- virtualbox-kernel-desktop-latest-6.1.20-1.1.mga8.x86_64

reboot

$ sudo dkms status
virtualbox, 6.1.20-1.1.mga8, 5.10.30-desktop-1.mga8, x86_64: installed 
nvidia-current, 460.67-1.mga8.nonfree, 5.10.27-desktop-1.mga8, x86_64: installed 
nvidia-current, 460.67-1.mga8.nonfree, 5.10.30-desktop-1.mga8, x86_64: installed 
virtualbox, 6.1.18-2.mga8, 5.10.27-desktop-1.mga8, x86_64: installed-binary from 5.10.27-desktop-1.mga8
virtualbox, 6.1.20-1.1.mga8, 5.10.30-desktop-1.mga8, x86_64: installed-binary from 5.10.30-desktop-1.mga8

Extpack from virtualbox site istalled manually as usual for me Bug 18962.

Running MSW7 64 bit. 

Virtualbox downloaded guest addidions its popup request and my grant but put them in another folder than it use to find them from.  Hm upstream change?  Moved manually and installed, reboot guest.

Shared clipboard, shared folders one full access and one read only.  Dynamic window resize.  Internet video in Firefox.  USB memory stick.

CC: (none) => fri

Comment 4 Thomas Andrews 2021-04-23 17:44:17 CEST
i5 2500, Intel graphics, wired Internet connection, 64-bit MGA8 Plasma system.

I don't use dkms, preferring to rely on our kmods instead. Packages installed cleanly. Extension pack downloaded manually and updated using the Vbox gui without issues, as usual.

Ran a Windows XP guest that hadn't been used in months, which scolded me for not keeping my anti-malware up to date. Anti-malware updated and new guest additions downloaded and inserted without incident. Rebooted to a desktop that was working as well as XP ever works.

Ran a Mageia 8 Plasma guest that also had not been run in a while, updated it, then used qarepo to update to the guest additions in Comment 0. Rebooted, because the guest kernel had been updated, to a working desktop.

Looks good on this install. This is a test install on this hardware, with fewer guests than on my production install. Next step is to update vbox on that production install.

CC: (none) => andrewsfarm

Comment 5 Aurelien Oudelet 2021-04-23 19:44:28 CEST
Mageia 8 x86_64 Plasma

Virtualbox update OK.
DKMS rebuild OK
Note Kmod one installs OK on an other computer.

Linux Guests OK
Windows Guest OK

Shared clipboard OK

OK to go.

CC: (none) => ouaurelien

Comment 6 Dave Hodgins 2021-04-23 20:18:38 CEST
No regressions noticed. File picker is working with mouse again.

Validating the update.

Whiteboard: MGA7TOO => MGA7TOO MGA8-64-OK MGA7-64-OK
CC: (none) => davidwhodgins, sysadmin-bugs
Keywords: (none) => validated_update

Comment 7 Aurelien Oudelet 2021-04-23 20:50:50 CEST
Advisory:
========================

Updated virtualbox packages provide bugfix release

This is a maintenance release. See upstream advisory for fixes and additions.

This also fixes several Bugs in our Bugzilla:
 - a zombie spawning process for Virtualbox (mga#27362)
 - a fix for Extension Pack supplied by our packages (mga#27936)
 - VboxREM is gone by default in 6.1, but vbox install scripts installs the symlink anyway, this is fixed in this release (mga#28734).

References:
- https://bugs.mageia.org/show_bug.cgi?id=28828
- https://bugs.mageia.org/show_bug.cgi?id=27362
- https://bugs.mageia.org/show_bug.cgi?id=27936
- https://bugs.mageia.org/show_bug.cgi?id=28734
- https://www.virtualbox.org/wiki/Changelog
========================

Updated packages from 7/core/updates_testing:
========================

*** Arch: i586 ***
dkms-vboxadditions-6.1.20-1.mga7.noarch.rpm
virtualbox-6.1.20-1.mga7.i586.rpm
virtualbox-guest-additions-6.1.20-1.mga7.i586.rpm

*** Arch: x86_64 ***
dkms-vboxadditions-6.1.20-1.mga7.noarch.rpm
dkms-virtualbox-6.1.20-1.mga7.x86_64.rpm
python-virtualbox-6.1.20-1.mga7.x86_64.rpm
virtualbox-6.1.20-1.mga7.x86_64.rpm
virtualbox-devel-6.1.20-1.mga7.x86_64.rpm
virtualbox-guest-additions-6.1.20-1.mga7.x86_64.rpm
virtualbox-kernel-5.10.30-desktop-1.mga7-6.1.20-1.mga7.x86_64.rpm
virtualbox-kernel-5.10.30-server-1.mga7-6.1.20-1.mga7.x86_64.rpm
virtualbox-kernel-desktop-latest-6.1.20-1.mga7.x86_64.rpm
virtualbox-kernel-server-latest-6.1.20-1.mga7.x86_64.rpm

from SRPM:
kmod-virtualbox-6.1.20-1.mga7.src.rpm
virtualbox-6.1.20-1.mga7.src.rpm

========================

Updated packages from 8/core/updates_testing:
========================

*** Arch: i586 ***
virtualbox-6.1.20-1.1.mga8.i586.rpm
virtualbox-guest-additions-6.1.20-1.1.mga8.i586.rpm

*** Arch: x86_64 ***
dkms-virtualbox-6.1.20-1.1.mga8.x86_64.rpm
python-virtualbox-6.1.20-1.1.mga8.x86_64.rpm
virtualbox-6.1.20-1.1.mga8.x86_64.rpm
virtualbox-devel-6.1.20-1.1.mga8.x86_64.rpm
virtualbox-guest-additions-6.1.20-1.1.mga8.x86_64.rpm
virtualbox-kernel-5.10.30-desktop-1.mga8-6.1.20-1.1.mga8.x86_64.rpm
virtualbox-kernel-5.10.30-server-1.mga8-6.1.20-1.1.mga8.x86_64.rpm
virtualbox-kernel-desktop-latest-6.1.20-1.1.mga8.x86_64.rpm
virtualbox-kernel-server-latest-6.1.20-1.1.mga8.x86_64.rpm

from SRPM:
kmod-virtualbox-6.1.20-1.1.mga8.src.rpm
virtualbox-6.1.20-1.1.mga8.src.rpm
Aurelien Oudelet 2021-04-23 20:52:04 CEST

Keywords: (none) => advisory

Comment 8 Thomas Backlund 2021-04-23 20:54:33 CEST
not so fast...  I need to add the security info bits too

Keywords: validated_update => (none)

Comment 9 Thomas Backlund 2021-04-23 20:56:53 CEST
ref:
https://www.oracle.com/security-alerts/cpuapr2021.html#AppendixOVIR

and a lot of CVE info to add
Comment 10 Dave Hodgins 2021-04-23 21:38:42 CEST
cve entries for virtualbox (excluding the windows only one) added to the advisory.
Thomas Backlund 2021-04-23 23:34:38 CEST

Keywords: (none) => validated_update
Blocks: (none) => 27433

Comment 11 Mageia Robot 2021-04-24 00:55:01 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0197.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.