Bug 29879 - Update request: kernel-5.15.15-1.mga8
Summary: Update request: kernel-5.15.15-1.mga8
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK, MGA8-32-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-01-12 17:33 CET by Thomas Backlund
Modified: 2022-01-18 16:44 CET (History)
9 users (show)

See Also:
Source RPM: kernel
CVE:
Status comment:


Attachments

Description Thomas Backlund 2022-01-12 17:33:47 CET
Security and bugfixes, advisory will follow...


SRPMS:
kernel-5.15.14-1.mga8.src.rpm
kmod-virtualbox-6.1.30-1.10.mga8.src.rpm
kmod-xtables-addons-3.18-1.44.mga8.src.rpm



i586:
bpftool-5.15.14-1.mga8.i586.rpm
cpupower-5.15.14-1.mga8.i586.rpm
cpupower-devel-5.15.14-1.mga8.i586.rpm
kernel-desktop-5.15.14-1.mga8-1-1.mga8.i586.rpm
kernel-desktop586-5.15.14-1.mga8-1-1.mga8.i586.rpm
kernel-desktop586-devel-5.15.14-1.mga8-1-1.mga8.i586.rpm
kernel-desktop586-devel-latest-5.15.14-1.mga8.i586.rpm
kernel-desktop586-latest-5.15.14-1.mga8.i586.rpm
kernel-desktop-devel-5.15.14-1.mga8-1-1.mga8.i586.rpm
kernel-desktop-devel-latest-5.15.14-1.mga8.i586.rpm
kernel-desktop-latest-5.15.14-1.mga8.i586.rpm
kernel-doc-5.15.14-1.mga8.noarch.rpm
kernel-server-5.15.14-1.mga8-1-1.mga8.i586.rpm
kernel-server-devel-5.15.14-1.mga8-1-1.mga8.i586.rpm
kernel-server-devel-latest-5.15.14-1.mga8.i586.rpm
kernel-server-latest-5.15.14-1.mga8.i586.rpm
kernel-source-5.15.14-1.mga8-1-1.mga8.noarch.rpm
kernel-source-latest-5.15.14-1.mga8.noarch.rpm
kernel-userspace-headers-5.15.14-1.mga8.i586.rpm
libbpf0-5.15.14-1.mga8.i586.rpm
libbpf-devel-5.15.14-1.mga8.i586.rpm
perf-5.15.14-1.mga8.i586.rpm

xtables-addons-kernel-5.15.14-desktop-1.mga8-3.18-1.44.mga8.i586.rpm
xtables-addons-kernel-5.15.14-desktop586-1.mga8-3.18-1.44.mga8.i586.rpm
xtables-addons-kernel-5.15.14-server-1.mga8-3.18-1.44.mga8.i586.rpm
xtables-addons-kernel-desktop586-latest-3.18-1.44.mga8.i586.rpm
xtables-addons-kernel-desktop-latest-3.18-1.44.mga8.i586.rpm
xtables-addons-kernel-server-latest-3.18-1.44.mga8.i586.rpm



x86_64:
bpftool-5.15.14-1.mga8.x86_64.rpm
cpupower-5.15.14-1.mga8.x86_64.rpm
cpupower-devel-5.15.14-1.mga8.x86_64.rpm
kernel-desktop-5.15.14-1.mga8-1-1.mga8.x86_64.rpm
kernel-desktop-devel-5.15.14-1.mga8-1-1.mga8.x86_64.rpm
kernel-desktop-devel-latest-5.15.14-1.mga8.x86_64.rpm
kernel-desktop-latest-5.15.14-1.mga8.x86_64.rpm
kernel-doc-5.15.14-1.mga8.noarch.rpm
kernel-server-5.15.14-1.mga8-1-1.mga8.x86_64.rpm
kernel-server-devel-5.15.14-1.mga8-1-1.mga8.x86_64.rpm
kernel-server-devel-latest-5.15.14-1.mga8.x86_64.rpm
kernel-server-latest-5.15.14-1.mga8.x86_64.rpm
kernel-source-5.15.14-1.mga8-1-1.mga8.noarch.rpm
kernel-source-latest-5.15.14-1.mga8.noarch.rpm
kernel-userspace-headers-5.15.14-1.mga8.x86_64.rpm
lib64bpf0-5.15.14-1.mga8.x86_64.rpm
lib64bpf-devel-5.15.14-1.mga8.x86_64.rpm
perf-5.15.14-1.mga8.x86_64.rpm

virtualbox-kernel-5.15.14-desktop-1.mga8-6.1.30-1.10.mga8.x86_64.rpm
virtualbox-kernel-5.15.14-server-1.mga8-6.1.30-1.10.mga8.x86_64.rpm
virtualbox-kernel-desktop-latest-6.1.30-1.10.mga8.x86_64.rpm
virtualbox-kernel-server-latest-6.1.30-1.10.mga8.x86_64.rpm

xtables-addons-kernel-5.15.14-desktop-1.mga8-3.18-1.44.mga8.x86_64.rpm
xtables-addons-kernel-5.15.14-server-1.mga8-3.18-1.44.mga8.x86_64.rpm
xtables-addons-kernel-desktop-latest-3.18-1.44.mga8.x86_64.rpm
xtables-addons-kernel-server-latest-3.18-1.44.mga8.x86_64.rpm
Comment 1 Jose Manuel López 2022-01-13 11:26:42 CET
Updated from 5.15.11 in Mga8 Vbox x64. All ok for the moment, boot without issues.

Applications ok, internet ok, sound and video ok.

Greetings!

CC: (none) => joselpddj

Comment 2 Morgan Leijström 2022-01-13 12:26:59 CET
OK here mga8-64, nvidia-current

Here *Not* yet using testing repos mesa 21.3.4, libdrm 2.4.109, nvidia-cuda-toolkit 11.4.3-1

Installed:
- cpupower-5.15.14-1.mga8.x86_64
- kernel-desktop-5.15.14-1.mga8-1-1.mga8.x86_64
- kernel-desktop-devel-5.15.14-1.mga8-1-1.mga8.x86_64
- kernel-desktop-devel-latest-5.15.14-1.mga8.x86_64
- kernel-desktop-latest-5.15.14-1.mga8.x86_64
- kernel-userspace-headers-5.15.14-1.mga8.x86_64
- lib64bpf0-5.15.14-1.mga8.x86_64
- virtualbox-kernel-5.15.14-desktop-1.mga8-6.1.30-1.10.mga8.x86_64
- virtualbox-kernel-desktop-latest-6.1.30-1.10.mga8.x86_64

Rebooted,

$ uname -a
Linux svarten.tribun 5.15.14-desktop-1.mga8 #1 SMP Tue Jan 11 18:39:25 UTC 2022 x86_64 x86_64 x86_64 GNU/Linux

$ dkms status showing OK

BOINC detects CUDA and OpenCL, and BOINC perform work on GPU
  (sidenote:  I have told before i have had OpenPandemics COVID-19 work get calculation faults after being interrupted by user using computer, and I said that have stopped, but it simply comes and goes with previous as well as this kernel and nvidia.  Maybe it is just incompatible with my old GPU)


Hardware:
  My workstation "svarten": Mainboard: Sabertooth P67, CPU: i7-3770, RAM 16G, GM107 [GeForce GTX 750] using nvidia-current; GeForce 635 series and later, 4k display.  Disk&Filesystem: SSD with /boot/EFI and ext4 /boot, LUKS{LVM {swap, ext4 /home & / } and a spinner at /mnt/spinner


Tested:

  Plasma desktop; using Thunderbird, LibreOffice, Ktorrent, Nextcloud client, Firefox ESR, flatpak Firefox, flatpak Spotify, java program FriBOK, ... 
Stress test: While working with other things BOINC use all cores to 100%, videos do not stutter in Chromium, nor Firefox ESR but do in flatpak version (except, note to self: why do not this clip stutter? https://www.svtplay.se/video/33779850/einar-2002-2021)

 VirtualBox: Launched my usual MSW7pro-64, tests OK: bidirectional clipboard, shared folders write protected and not, USB2 memory stick read&write (using upstream extension pack), drag file from Dolphin to Windows Explorer, Windows update, video playing in Firefox and Chrome while CPU is heavily loaded.
(As before drag of file in Windows Explorer to Dolphin does not work, despite bidirectional drag is enabled and the cursor outside VirtualBox client window transforms to a green plus.)

CC: (none) => fri

Comment 3 Herman Viaene 2022-01-13 14:55:50 CET
MGA8-64 Plasma on Lenovo B50 in Dutch
No installation issues.
Rebooted after installing the server version, went OK.Tested various file types (odt, ods odp, odb, pdf, gifn jpg, avi), all OK.Access to internet OK and access to NFS-shares on LAN works OK.

CC: (none) => herman.viaene

Comment 4 Len Lawrence 2022-01-13 20:26:31 CET
Mageia8, x64
Desktop and server kernels have been working fine on this Intel9 machine today.nvidia graphics.  Bluetooth works out of the box.  Virtualbox OK as well.

Server kernel also tested on an Intel7 machine with nvidia.  No regressions noted.

CC: (none) => tarazed25

Comment 5 Len Lawrence 2022-01-13 22:55:56 CET
mga8, x64

Tried  desktop and server kernels on Intel NUC10i7FNB, Intel Comet Lake UHD Graphics (i915).
Everything working as it should in Mate, including bluetooth, which needed no reconfiguration.  Tainted vlc worked fine in skinned mode once I remembered to install svlc.
Comment 6 Morgan Leijström 2022-01-14 15:21:40 CET
Also OK mga8-64 in Thinkapd T510

64-bit Plasma, VirtualBox with W10 client. 
HW: i5 M540  Nvidia GT218M(NVC3100M) using Geforce 8100 to 415 driver.
No regression noted.  Suspend-resume works.

Hibernate fails: saves everything, according to log, but fail to shut off, and also restart dont read back what was saved.
Have never tried this before, this installation is new on a bought used laptop so i dont know if it is a regression or not. / in encrypted LVM, separate /boot

For another bug report. Another week.
Comment 7 William Kenney 2022-01-14 19:50:13 CET
On M8 hardware in a Vbox client, M8, Xfce, 32-bit

clear
uname -a
urpmi kernel-desktop-latest
urpmi kernel-userspace-headers
urpmi cpupower
urpmi virtualbox-guest-additions

Linux localhost 5.15.11-desktop586-3.mga8 #1 SMP Sat Dec 25 10:44:38 UTC 2021 i686 i686 i386 GNU/Linux
Package kernel-desktop-latest-5.15.11-3.mga8.i586 is already installed
Package kernel-userspace-headers-5.15.11-3.mga8.i586 is already installed
Package cpupower-5.15.11-3.mga8.i586 is already installed
Package virtualbox-guest-additions-6.1.30-1.mga8.i586 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

install updates from from update_testing:
 
Reboot system.

Linux localhost 5.15.14-desktop-1.mga8 #1 SMP Tue Jan 11 18:20:56 UTC 2022 i686 i686 i386 GNU/Linux
Package kernel-desktop-latest-5.15.14-1.mga8.i586 is already installed
Package kernel-userspace-headers-5.15.14-1.mga8.i586 is already installed
Package cpupower-5.15.14-1.mga8.i586 is already installed
Package virtualbox-guest-additions-6.1.30-1.mga8.i586 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

CC: (none) => wilcal.int

Comment 8 William Kenney 2022-01-14 19:51:26 CET
On M8 hardware in a Vbox client, M8, Plasma, 64-bit

clear
uname -a
urpmi kernel-desktop-latest
urpmi kernel-userspace-headers
urpmi cpupower
urpmi virtualbox-guest-additions

Linux localhost 5.15.11-desktop-3.mga8 #1 SMP Sat Dec 25 10:44:47 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux
Package kernel-desktop-latest-5.15.11-3.mga8.x86_64 is already installed
Package kernel-userspace-headers-5.15.11-3.mga8.x86_64 is already installed
Package cpupower-5.15.11-3.mga8.x86_64 is already installed
Package virtualbox-guest-additions-6.1.30-1.mga8.x86_64 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

install updates from from update_testing:

Reboot system.

Linux localhost 5.15.14-desktop-1.mga8 #1 SMP Tue Jan 11 18:39:25 UTC 2022 x86_64 x86_64 x86_64 GNU/Linux
Package kernel-desktop-latest-5.15.14-1.mga8.x86_64 is already installed
Package kernel-userspace-headers-5.15.14-1.mga8.x86_64 is already installed
Package cpupower-5.15.14-1.mga8.x86_64 is already installed
Package virtualbox-guest-additions-6.1.30-1.mga8.x86_64 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.
Comment 9 William Kenney 2022-01-14 19:53:04 CET
On real hardware, M8, Plasma, 64-bit

Packages checked:

clear
uname -a
urpmi kernel-desktop-latest
urpmi virtualbox
urpmi x11-driver-video-vboxvideo
urpmi kernel-desktop-devel-latest
urpmi kernel-userspace-headers
urpmi cpupower
urpmi virtualbox-kernel-desktop-latest
urpmi dkms-virtualbox
 
Linux localhost 5.15.11-desktop-3.mga8 #1 SMP Sat Dec 25 10:44:47 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux
Package kernel-desktop-latest-5.15.11-3.mga8.x86_64 is already installed
Package virtualbox-6.1.30-1.mga8.x86_64 is already installed
Package x11-driver-video-vboxvideo-1.0.0-6.mga8.x86_64 is already installed
Package kernel-desktop-devel-latest-5.15.11-3.mga8.x86_64 is already installed
Package kernel-userspace-headers-5.15.11-3.mga8.x86_64 is already installed
Package cpupower-5.15.11-3.mga8.x86_64 is already installed
Package virtualbox-kernel-desktop-latest-6.1.30-1.7.mga8.x86_64 is already installed
Package dkms-virtualbox-6.1.30-1.mga8.x86_64 is already installed
[root@localhost wilcal]# lspci -k
00:02.0 VGA compatible controller: Intel Corporation Iris Plus Graphics G1 (Ice Lake) (rev 07)
        DeviceName: To Be Filled by O.E.M.
        Subsystem: Dell Device 097c
        Kernel driver in use: i915
        Kernel modules: i915

Boots to working desktop

M8   i586   Vbox Xfce   Client, boots to a working desktop - Screen size correct
M8   x86_64 Vbox Plasma Client, boots to a working desktop - Screen size correct

install updates from from update_testing:

reboot system

Linux localhost 5.15.14-desktop-1.mga8 #1 SMP Tue Jan 11 18:39:25 UTC 2022 x86_64 x86_64 x86_64 GNU/Linux
Package kernel-desktop-latest-5.15.14-1.mga8.x86_64 is already installed
Package virtualbox-6.1.30-1.mga8.x86_64 is already installed
Package x11-driver-video-vboxvideo-1.0.0-6.mga8.x86_64 is already installed
Package kernel-desktop-devel-latest-5.15.14-1.mga8.x86_64 is already installed
Package kernel-userspace-headers-5.15.14-1.mga8.x86_64 is already installed
Package cpupower-5.15.14-1.mga8.x86_64 is already installed
Package virtualbox-kernel-desktop-latest-6.1.30-1.10.mga8.x86_64 is already installed
Package dkms-virtualbox-6.1.30-1.mga8.x86_64 is already installed
[root@localhost wilcal]# lspci -k
00:02.0 VGA compatible controller: Intel Corporation Iris Plus Graphics G1 (Ice Lake) (rev 07)
        DeviceName: To Be Filled by O.E.M.
        Subsystem: Dell Device 097c
        Kernel driver in use: i915
        Kernel modules: i915

M8   i586   Vbox Xfce   Client, boots to a working desktop - Screen size correct
M8   x86_64 Vbox Plasma Client, boots to a working desktop - Screen size correct
Comment 10 Thomas Backlund 2022-01-14 21:40:03 CET
Putting on hold, a more complete fix for a security issue is coming in 5.15.15 in a day or so...

Keywords: (none) => feedback

Comment 11 Thomas Backlund 2022-01-16 12:55:19 CET
New set...

SRPMS:
kernel-5.15.15-1.mga8.src.rpm
kmod-virtualbox-6.1.30-1.12.mga8.src.rpm
kmod-xtables-addons-3.18-1.46.mga8.src.rpm



i586:
bpftool-5.15.15-1.mga8.i586.rpm
cpupower-5.15.15-1.mga8.i586.rpm
cpupower-devel-5.15.15-1.mga8.i586.rpm
kernel-desktop-5.15.15-1.mga8-1-1.mga8.i586.rpm
kernel-desktop586-5.15.15-1.mga8-1-1.mga8.i586.rpm
kernel-desktop586-devel-5.15.15-1.mga8-1-1.mga8.i586.rpm
kernel-desktop586-devel-latest-5.15.15-1.mga8.i586.rpm
kernel-desktop586-latest-5.15.15-1.mga8.i586.rpm
kernel-desktop-devel-5.15.15-1.mga8-1-1.mga8.i586.rpm
kernel-desktop-devel-latest-5.15.15-1.mga8.i586.rpm
kernel-desktop-latest-5.15.15-1.mga8.i586.rpm
kernel-doc-5.15.15-1.mga8.noarch.rpm
kernel-server-5.15.15-1.mga8-1-1.mga8.i586.rpm
kernel-server-devel-5.15.15-1.mga8-1-1.mga8.i586.rpm
kernel-server-devel-latest-5.15.15-1.mga8.i586.rpm
kernel-server-latest-5.15.15-1.mga8.i586.rpm
kernel-source-5.15.15-1.mga8-1-1.mga8.noarch.rpm
kernel-source-latest-5.15.15-1.mga8.noarch.rpm
kernel-userspace-headers-5.15.15-1.mga8.i586.rpm
libbpf0-5.15.15-1.mga8.i586.rpm
libbpf-devel-5.15.15-1.mga8.i586.rpm
perf-5.15.15-1.mga8.i586.rpm

xtables-addons-kernel-5.15.15-desktop-1.mga8-3.18-1.46.mga8.i586.rpm
xtables-addons-kernel-5.15.15-desktop586-1.mga8-3.18-1.46.mga8.i586.rpm
xtables-addons-kernel-5.15.15-server-1.mga8-3.18-1.46.mga8.i586.rpm
xtables-addons-kernel-desktop586-latest-3.18-1.46.mga8.i586.rpm
xtables-addons-kernel-desktop-latest-3.18-1.46.mga8.i586.rpm
xtables-addons-kernel-server-latest-3.18-1.46.mga8.i586.rpm



x86_64:
bpftool-5.15.15-1.mga8.x86_64.rpm
cpupower-5.15.15-1.mga8.x86_64.rpm
cpupower-devel-5.15.15-1.mga8.x86_64.rpm
kernel-desktop-5.15.15-1.mga8-1-1.mga8.x86_64.rpm
kernel-desktop-devel-5.15.15-1.mga8-1-1.mga8.x86_64.rpm
kernel-desktop-devel-latest-5.15.15-1.mga8.x86_64.rpm
kernel-desktop-latest-5.15.15-1.mga8.x86_64.rpm
kernel-doc-5.15.15-1.mga8.noarch.rpm
kernel-server-5.15.15-1.mga8-1-1.mga8.x86_64.rpm
kernel-server-devel-5.15.15-1.mga8-1-1.mga8.x86_64.rpm
kernel-server-devel-latest-5.15.15-1.mga8.x86_64.rpm
kernel-server-latest-5.15.15-1.mga8.x86_64.rpm
kernel-source-5.15.15-1.mga8-1-1.mga8.noarch.rpm
kernel-source-latest-5.15.15-1.mga8.noarch.rpm
kernel-userspace-headers-5.15.15-1.mga8.x86_64.rpm
lib64bpf0-5.15.15-1.mga8.x86_64.rpm
lib64bpf-devel-5.15.15-1.mga8.x86_64.rpm
perf-5.15.15-1.mga8.x86_64.rpm

virtualbox-kernel-5.15.15-desktop-1.mga8-6.1.30-1.12.mga8.x86_64.rpm
virtualbox-kernel-5.15.15-server-1.mga8-6.1.30-1.12.mga8.x86_64.rpm
virtualbox-kernel-desktop-latest-6.1.30-1.12.mga8.x86_64.rpm
virtualbox-kernel-server-latest-6.1.30-1.12.mga8.x86_64.rpm

xtables-addons-kernel-5.15.15-desktop-1.mga8-3.18-1.46.mga8.x86_64.rpm
xtables-addons-kernel-5.15.15-server-1.mga8-3.18-1.46.mga8.x86_64.rpm
xtables-addons-kernel-desktop-latest-3.18-1.46.mga8.x86_64.rpm
xtables-addons-kernel-server-latest-3.18-1.46.mga8.x86_64.rpm

Keywords: feedback => (none)
Summary: Update request: kernel-5.15.14-1.mga8 => Update request: kernel-5.15.15-1.mga8

Comment 12 Guillaume Royer 2022-01-16 20:46:28 CET
MGA X64 XFCE, Core I3, 4Go Ram, Nvidia 520M Driver 390, Driver Broadcom non free.

Updated with QA repo and rpms:

cpupower                       5.15.15      1.mga8        x86_64  
kernel-desktop-5.15.15-1.mga8  1            1.mga8        x86_64  
kernel-desktop-devel-5.15.15-> 1            1.mga8        x86_64  
kernel-desktop-devel-latest    5.15.15      1.mga8        x86_64  
kernel-desktop-latest          5.15.15      1.mga8        x86_64  
kernel-userspace-headers       5.15.15      1.mga8        x86_64  
lib64bpf0                      5.15.15      1.mga8        x86_64  
virtualbox-kernel-5.15.15-des> 6.1.30       1.12.mga8     x86_64  
virtualbox-kernel-desktop-lat> 6.1.30       1.12.mga8     x86_64 

No issues after reboot, 
switching with mageia-prime ok, 
web browsing ok,
VM functionnal

====================================================================

MGA X64 LxQt Asus Transformer T100A TA 2 Go, Atom processor

Updated with QA repo and rpm:

cpupower                       5.15.15      1.mga8        x86_64  
kernel-desktop-5.15.15-1.mga8  1            1.mga8        x86_64  
kernel-desktop-latest          5.15.15      1.mga8        x86_64  
kernel-userspace-headers       5.15.15      1.mga8        x86_64  
lib64bpf0                      5.15.15      1.mga8        x86_64 

No issues after reboot, sounds issues are still there

CC: (none) => guillaume.royer

Comment 13 Thomas Andrews 2022-01-17 00:03:57 CET
i5-2500, Intel graphics, wired Internet and rtl8192eu wifi, 64-bit Plasma system using the server kernel.

The following 9 packages are going to be installed:

- cpupower-5.15.15-1.mga8.x86_64
- kernel-server-5.15.15-1.mga8-1-1.mga8.x86_64
- kernel-server-devel-5.15.15-1.mga8-1-1.mga8.x86_64
- kernel-server-devel-latest-5.15.15-1.mga8.x86_64
- kernel-server-latest-5.15.15-1.mga8.x86_64
- kernel-userspace-headers-5.15.15-1.mga8.x86_64
- lib64bpf0-5.15.15-1.mga8.x86_64
- virtualbox-kernel-5.15.15-server-1.mga8-6.1.30-1.12.mga8.x86_64
- virtualbox-kernel-server-latest-6.1.30-1.12.mga8.x86_64

No installation issues. The rtl8192eu and virtualbox modules built successfully. After the reboot, tried running a M8 guest in Virtualbox, ran Firefox, switched to wifi and tried Firefox again, played a video with vlc. 

No issues noted.

CC: (none) => andrewsfarm

Comment 14 Jose Manuel López 2022-01-17 10:01:56 CET
Ok here, installed in Vbox Mga8 Intel I5 wiht intel graphics.

Reboot ok, no installation issues, wifi ok, apps ok, libreoffice ok, firefox ok, youtube ok, sound ok. 

Greetings!!
Comment 15 Len Lawrence 2022-01-17 13:34:14 CET
Installed desktop and server kernels and all the other packages save source.  Completely smooth transition from kernel linus to the new desktop version on Mate.  Everything in place and working.

10-Core Intel Core i9-7900X
NVIDIA GeForce GTX 1080 Ti
Comment 16 Thomas Backlund 2022-01-17 18:08:33 CET
Advisory, added to svn:

type: security
subject: Updated kernel packages fix security vulnerabilities
CVE:
 - CVE-2021-4155
 - CVE-2021-4197
 - CVE-2021-4204
 - CVE-2021-44733
 - CVE-2021-45095
 - CVE-2021-45100
 - CVE-2022-23222
src:
  8:
   core:
     - kernel-5.15.15-1.mga8
     - kmod-virtualbox-6.1.30-1.12.mga8
     - kmod-xtables-addons-3.18-1.46.mga8
description: |
  This kernel update is based on upstream 5.15.15 and fixes atleast the
  following security issues:

  A data leak flaw was found in the way XFS_IOC_ALLOCSP IOCTL in the XFS
  filesystem allowed for size increase of files with unaligned size. A
  local attacker could use this flaw to leak data on the XFS filesystem
  otherwise not accessible to them (CVE-2021-4155).

  An unprivileged write to the file handler flaw in the Linux kernel's
  control groups and namespaces subsystem was found in the way users have
  access to some less privileged process that are controlled by cgroups and
  have higher privileged parent process. It is actually both for cgroup2
  and cgroup1 versions of control groups. A local user could use this flaw
  to crash the system or escalate their privileges on the system
  (CVE-2021-4197).

  Lack of proper validation of user-supplied eBPF programs prior to executing
  them. An attacker can leverage this vulnerability to escalate privileges
  and execute code in the context of the kernel (CVE-2021-4204).

  A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in
  the Linux kernel through 5.15.11. This occurs because of a race condition
  in tee_shm_get_from_id during an attempt to free a shared memory object
  (CVE-2021-44733).

  pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8
  has a refcount leak (CVE-2021-45095).

  The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8,
  sometimes communicates in cleartext even though encryption has been enabled.
  This occurs because it sets the SMB2_GLOBAL_CAP_ENCRYPTION flag when using
  the SMB 3.1.1 protocol, which is a violation of the SMB protocol
  specification. When Windows 10 detects this protocol violation, it disables
  encryption (CVE-2021-45100).

  kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local
  users to gain privileges because of the availability of pointer arithmetic
  via certain *_OR_NULL pointer types (CVE-2022-23222).

  In addition to the upstream changes, we also have changed the following:
  - iwlwifi: mvm: check if SAR GEO is supported before sending command
  - select: Fix indefinitely sleeping task in poll_schedule_timeout()
  - ALSA: hda: Add AlderLake-N/P PCI ID
  - enable NF_TABLES_INET, NFT_REJECT_INET and NFT_FIB_INET (mga#29852)
  - disable CIFS_SMB_DIRECT on desktop kernels as it makes loading cifs
    deps fail on some setups (mga#29784)
  - disable unprivileged bpf by default to mitigate other potential security
    issues with bpf

  For other upstream fixes, see the referenced changelogs.
references:
 - https://bugs.mageia.org/show_bug.cgi?id=29879
 - https://bugs.mageia.org/show_bug.cgi?id=29852
 - https://bugs.mageia.org/show_bug.cgi?id=29784
 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.12
 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.13
 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.14
 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.15

Keywords: (none) => advisory

Comment 17 Len Lawrence 2022-01-17 18:38:45 CET
mga8, x64.  No installation or reboot issues.
Desktop kernel works fine on Intel Core i7, nVidia GTX 970.
VirtualBox OK.  Bluetooth audio, vlc video, no problem.
Leaving this up for a while.
Comment 18 Dave Hodgins 2022-01-17 19:13:35 CET
No regressions noticed on any of my installs.
- x86_64 desktop
  - vb i586 guest
  - vb x86_64 guest
- x86_64 laptop
- aarch64 rpi4

CC: (none) => davidwhodgins

Comment 19 Morgan Leijström 2022-01-17 20:09:05 CET
OK 64bit desktop-5.15.15-1
Same tests as comment 2 & comment 3
Comment 20 Thomas Andrews 2022-01-17 20:59:16 CET
Tested on Foolishness, a Dell Inspiron 5100, P4, Radeon RV200 graphics, old Atheros-based wifi, 32-bit Xfce system using the desktop kernel.

No installation issues. After the reboot, loaded a spreadsheet into Libreoffice, played a video with Parole, visited some websites with Firefox. Youtube videos don't play well because of the limits of the hardware, no change there. Videos from mp4 files on the ssd play much better.

No issues noted.
Comment 21 William Kenney 2022-01-18 04:55:06 CET
On M8 hardware in a Vbox client, M8, Xfce, 32-bit

clear
uname -a
urpmi kernel-desktop-latest
urpmi kernel-userspace-headers
urpmi cpupower
urpmi virtualbox-guest-additions

Linux localhost 5.15.11-desktop586-3.mga8 #1 SMP Sat Dec 25 10:44:38 UTC 2021 i686 i686 i386 GNU/Linux
Package kernel-desktop-latest-5.15.11-3.mga8.i586 is already installed
Package kernel-userspace-headers-5.15.11-3.mga8.i586 is already installed
Package cpupower-5.15.11-3.mga8.i586 is already installed
Package virtualbox-guest-additions-6.1.30-1.mga8.i586 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

install updates from from update_testing:

Reboot system.

Linux localhost 5.15.15-desktop-1.mga8 #1 SMP Sun Jan 16 09:25:24 UTC 2022 i686 i686 i386 GNU/Linux
Package kernel-desktop-latest-5.15.15-1.mga8.i586 is already installed
Package kernel-userspace-headers-5.15.15-1.mga8.i586 is already installed
Package cpupower-5.15.15-1.mga8.i586 is already installed
Package virtualbox-guest-additions-6.1.30-1.mga8.i586 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.
Comment 22 William Kenney 2022-01-18 04:56:10 CET
On M8 hardware in a Vbox client, M8, Plasma, 64-bit

clear
uname -a
urpmi kernel-desktop-latest
urpmi kernel-userspace-headers
urpmi cpupower
urpmi virtualbox-guest-additions

Linux localhost 5.15.11-desktop-3.mga8 #1 SMP Sat Dec 25 10:44:47 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux
Package kernel-desktop-latest-5.15.11-3.mga8.x86_64 is already installed
Package kernel-userspace-headers-5.15.11-3.mga8.x86_64 is already installed
Package cpupower-5.15.11-3.mga8.x86_64 is already installed
Package virtualbox-guest-additions-6.1.30-1.mga8.x86_64 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.

install updates from from update_testing:

Reboot system.

Linux localhost 5.15.15-desktop-1.mga8 #1 SMP Sun Jan 16 08:49:42 UTC 2022 x86_64 x86_64 x86_64 GNU/Linux
Package kernel-desktop-latest-5.15.15-1.mga8.x86_64 is already installed
Package kernel-userspace-headers-5.15.15-1.mga8.x86_64 is already installed
Package cpupower-5.15.15-1.mga8.x86_64 is already installed
Package virtualbox-guest-additions-6.1.30-1.mga8.x86_64 is already installed

Boots to a working desktop. Screen resolution is correct. Common apps work.
Comment 23 William Kenney 2022-01-18 04:57:05 CET
On real hardware, M8, Plasma, 64-bit

Packages checked:

clear
uname -a
urpmi kernel-desktop-latest
urpmi virtualbox
urpmi x11-driver-video-vboxvideo
urpmi kernel-desktop-devel-latest
urpmi kernel-userspace-headers
urpmi cpupower
urpmi virtualbox-kernel-desktop-latest
urpmi dkms-virtualbox
 
Linux localhost 5.15.11-desktop-3.mga8 #1 SMP Sat Dec 25 10:44:47 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux
Package kernel-desktop-latest-5.15.11-3.mga8.x86_64 is already installed
Package virtualbox-6.1.30-1.mga8.x86_64 is already installed
Package x11-driver-video-vboxvideo-1.0.0-6.mga8.x86_64 is already installed
Package kernel-desktop-devel-latest-5.15.11-3.mga8.x86_64 is already installed
Package kernel-userspace-headers-5.15.11-3.mga8.x86_64 is already installed
Package cpupower-5.15.11-3.mga8.x86_64 is already installed
Package virtualbox-kernel-desktop-latest-6.1.30-1.7.mga8.x86_64 is already installed
Package dkms-virtualbox-6.1.30-1.mga8.x86_64 is already installed
[root@localhost wilcal]# lspci -k
00:02.0 VGA compatible controller: Intel Corporation Iris Plus Graphics G1 (Ice Lake) (rev 07)
        DeviceName: To Be Filled by O.E.M.
        Subsystem: Dell Device 097c
        Kernel driver in use: i915
        Kernel modules: i915

Boots to working desktop

M8   i586   Vbox Xfce   Client, boots to a working desktop - Screen size correct
M8   x86_64 Vbox Plasma Client, boots to a working desktop - Screen size correct

install updates from from update_testing:

reboot system

Linux localhost 5.15.15-desktop-1.mga8 #1 SMP Sun Jan 16 08:49:42 UTC 2022 x86_64 x86_64 x86_64 GNU/Linux
Package kernel-desktop-latest-5.15.15-1.mga8.x86_64 is already installed
Package virtualbox-6.1.30-1.mga8.x86_64 is already installed
Package x11-driver-video-vboxvideo-1.0.0-6.mga8.x86_64 is already installed
Package kernel-desktop-devel-latest-5.15.15-1.mga8.x86_64 is already installed
Package kernel-userspace-headers-5.15.15-1.mga8.x86_64 is already installed
Package cpupower-5.15.15-1.mga8.x86_64 is already installed
Package virtualbox-kernel-desktop-latest-6.1.30-1.12.mga8.x86_64 is already installed
Package dkms-virtualbox-6.1.30-1.mga8.x86_64 is already installed
[root@localhost wilcal]# lspci -k
00:02.0 VGA compatible controller: Intel Corporation Iris Plus Graphics G1 (Ice Lake) (rev 07)
        DeviceName: To Be Filled by O.E.M.
        Subsystem: Dell Device 097c
        Kernel driver in use: i915
        Kernel modules: i915

M8   i586   Vbox Xfce   Client, boots to a working desktop - Screen size correct
M8   x86_64 Vbox Plasma Client, boots to a working desktop - Screen size correct
Comment 24 Herman Viaene 2022-01-18 14:07:01 CET
Installed 5.15.15-server, no ill effect seen.
Comment 25 Thomas Backlund 2022-01-18 16:08:17 CET
Thanks for the tests...

Flushing out to get ahead of the bpf exploits getting disclosed...

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update
Whiteboard: (none) => MGA8-64-OK, MGA8-32-OK

Comment 26 Mageia Robot 2022-01-18 16:44:32 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0021.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.