Bug 29918 - Update request: virtualbox-6.1.32-1.mga8
Summary: Update request: virtualbox-6.1.32-1.mga8
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-01-20 23:32 CET by Thomas Backlund
Modified: 2022-01-26 20:52 CET (History)
6 users (show)

See Also:
Source RPM: virtualbox
CVE:
Status comment:


Attachments

Description Thomas Backlund 2022-01-20 23:32:11 CET
Security and bugfixes:

ref:
https://www.oracle.com/security-alerts/cpujan2022.html#AppendixOVIR
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21394
https://www.virtualbox.org/wiki/Changelog-6.1#v32



SRPM:
virtualbox-6.1.32-1.mga8.src.rpm


i586:
virtualbox-6.1.32-1.mga8.i586.rpm
virtualbox-guest-additions-6.1.32-1.mga8.i586.rpm


x86_64:
dkms-virtualbox-6.1.32-1.mga8.x86_64.rpm
python-virtualbox-6.1.32-1.mga8.x86_64.rpm
virtualbox-6.1.32-1.mga8.x86_64.rpm
virtualbox-devel-6.1.32-1.mga8.x86_64.rpm
virtualbox-guest-additions-6.1.32-1.mga8.x86_64.rpm


kmods will be built after bug 29916 is validated and puhed
Comment 1 David Walser 2022-01-21 20:30:07 CET
Wrong CVE identifier in Comment 0, should be:
CVE-2022-21295
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21295

(the other one only affects Windows)
Comment 2 Thomas Backlund 2022-01-22 11:34:11 CET
kmods

SRPM:
kmod-virtualbox-6.1.32-1.mga8.src.rpm

x86_64:
virtualbox-kernel-5.15.16-desktop-1.mga8-6.1.32-1.mga8.x86_64.rpm
virtualbox-kernel-5.15.16-server-1.mga8-6.1.32-1.mga8.x86_64.rpm
virtualbox-kernel-desktop-latest-6.1.32-1.mga8.x86_64.rpm
virtualbox-kernel-server-latest-6.1.32-1.mga8.x86_64.rpm
Comment 3 Thomas Backlund 2022-01-22 13:42:23 CET
(In reply to David Walser from comment #1)
> Wrong CVE identifier in Comment 0, should be:
> CVE-2022-21295
> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21295
> 
> (the other one only affects Windows)

Depends on who you want to belive:


https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21295
listed as Windows only

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21394
has no such reference...


https://www.oracle.com/security-alerts/cpujan2022.html#AppendixOVIR agrees with you now, but staded differently when I read it:
https://web.archive.org/web/20220119235014/https://www.oracle.com/security-alerts/cpujan2022.html#AppendixOVIR

:)
Comment 4 David Walser 2022-01-22 17:55:32 CET
How confusing :D
Comment 5 Guillaume Royer 2022-01-22 19:35:58 CET
MGA X64 updated with QA repo tool and rpms:

dkms-virtualbox                6.1.32       1.mga8        x86_64  
virtualbox                     6.1.32       1.mga8        x86_64  
virtualbox-kernel-5.15.16-des> 6.1.32       1.mga8        x86_64  
virtualbox-kernel-desktop-lat> 6.1.32       1.mga8        x86_64  

No issues at installation.
Tested on VM MGA Cauldron, 
internet browsing ok, 
update VM ok

no problems noted during the operation of the VM.

CC: (none) => guillaume.royer

Comment 6 Morgan Leijström 2022-01-22 21:27:27 CET
mga8-64, i7, nvidia-current, plasma, kernel-desktop-5.15.16-1

- dkms-virtualbox-6.1.32-1.mga8.x86_64
- virtualbox-6.1.32-1.mga8.x86_64
- virtualbox-kernel-5.15.16-desktop-1.mga8-6.1.32-1.mga8.x86_64
- virtualbox-kernel-desktop-latest-6.1.32-1.mga8.x86_64

rebooted,

dkms status is OK

I used command line to install the upstream extpack, for USB2 etc.

The guest system is MSW7pro 64 bit.

Performed the tests I use to:
  Used menu in guest machine window frame to have it fetch and connect guest extension, Windows installed it then, and i let it reboot.
  Dynamically resizing guest window by mouse
  Shared clipboard, bidirectional
  Shared folders bidirectional read/write copying, and readonly works correctly.
  Drag a file from host Dolphin to guest Explorer (as usual reverse dont work)
  USB2: flash FAT32 stick file read and write
  Sound, Internet, performance: playing video in Firefox
  Windows update (windows antivirus definitions)

CC: (none) => fri

Comment 7 Thomas Andrews 2022-01-22 23:02:01 CET
Intel i5-2500, Intel graphics, mga8-64 Plasma system.

Used qarepo to update Packages from Comments 0 and 2. No installation issues. Downloaded extension pack and used the vbox gui to update it. No issues there, either.

Ran a Win7 Pro guest, and told it to insert guest additions. They were downloaded and installed without incident, except that Windows complained that my anti-malware definitions needed to be updated. Ran a WinXP guest that I don't know why I keep around any more, and updated guest additions in that.

Ran a mga8-64 Plasma guest, used qarepo to get the guest additions, and updated that and the desktop kernel in one operation. Rebooted, without incident. Shared folders and bidirectional clipboard worked as they should.

I did not try to create a new guest, but everything else seems to be OK.

CC: (none) => andrewsfarm

Comment 8 christian barranco 2022-01-25 17:44:27 CET
Hi

```
System configuration:
=====================

System:    Host: cbct-desk Kernel: 5.15.16-desktop-1.mga8 x86_64 bits: 64 Desktop: KDE Plasma 5.20.4 Distro: Mageia 8 mga8 
Machine:   Type: Desktop System: ASUS product: N/A v: N/A serial: <superuser required> 
           Mobo: ASUSTeK model: TUF GAMING B550M-PLUS v: Rev X.0x serial: <superuser required> UEFI: American Megatrends 
           v: 2423 date: 08/10/2021 
CPU:       Info: 12-Core AMD Ryzen 9 5900X [MT MCP] speed: 4260 MHz min/max: 2200/3700 MHz 
Graphics:  Device-1: Advanced Micro Devices [AMD/ATI] Ellesmere [Radeon RX 470/480/570/570X/580/580X/590] driver: amdgpu 
           v: kernel 
           Display: x11 server: Mageia X.org 1.20.14 driver: amdgpu,v4l resolution: 2560x1440~60Hz 
           OpenGL: renderer: AMD Radeon RX 570 Series (POLARIS10 DRM 3.42.0 5.15.16-desktop-1.mga8 LLVM 11.0.1) 
           v: 4.6 Mesa 21.3.4 
Network:   Device-1: Realtek RTL8125 2.5GbE driver: r8169 
Drives:    Local Storage: total: 1.59 TiB used: 556.61 GiB (34.1%) 
           ID-1: /dev/nvme0n1 vendor: Seagate model: FireCuda 520 SSD ZP500GM30002 size: 465.76 GiB 
           ID-2: /dev/sda vendor: Western Digital model: WD10EZEX-00RKKA0 size: 931.51 GiB 
           ID-3: /dev/sdb vendor: Samsung model: SSD 850 EVO 250GB size: 232.89 GiB 
           Optical-1: /dev/sr0 vendor: HL-DT-ST model: DVDRAM GH24NS95 dev-links: cdrom,cdrw,dvd,dvdrw 
           Features: speed: 12 multisession: yes audio: yes dvd: yes rw: cd-r,cd-rw,dvd-r,dvd-ram 
USB:       Hub: 1-0:1 info: Full speed (or root) Hub ports: 10 rev: 2.0 
           Device-1: 1-6:2 info: ASUSTek AURA LED Controller type: <vendor specific> rev: 2.0 
           Hub: 1-7:3 info: Genesys Logic Hub ports: 4 rev: 2.0 
           Hub: 1-9:4 info: Genesys Logic Hub ports: 4 rev: 2.0 
           Hub: 2-0:1 info: Full speed (or root) Hub ports: 4 rev: 3.1 
           Hub: 3-0:1 info: Full speed (or root) Hub ports: 4 rev: 2.0 
           Device-1: 3-1:2 info: Logitech Unifying Receiver type: Keyboard,Mouse,HID rev: 2.0 
           Device-2: 3-2:3 info: Logitech HD Webcam C525 type: Audio,Video rev: 2.0 
           Device-3: 3-3:4 info: ASUSTek ASUS USB-BT500 type: Bluetooth rev: 1.1 
           Hub: 4-0:1 info: Full speed (or root) Hub ports: 4 rev: 3.1 

openCL AMD by installing manually some files of amdgpu-pro-20.20-1089974-rhel-8.2
```

```
UPDATE
======
Pour satisfaire les dépendances, les paquetages suivants vont être installés :
  Paquetage                      Version      Révision      Arch    
(média « QA Testing (64-bit) »)
  virtualbox                     6.1.32       1.mga8        x86_64  
  virtualbox-kernel-5.15.16-des> 6.1.32       1.mga8        x86_64  
  virtualbox-kernel-desktop-lat> 6.1.32       1.mga8        x86_64  
un espace additionnel de 10Ko sera utilisé.
39Mo de paquets seront récupérés.
Procéder à l'installation des 3 paquetages ? (O/n) 


installation de virtualbox-kernel-desktop-latest-6.1.32-1.mga8.x86_64.rpm virtualbox-kernel-5.15.16-desktop-1.mga8-6.1.32-1.mga8.x86_64.rpm virtualbox-6.1.32-1.mga8.x86_64.rpm depuis //data/share/qa-testing/x86_64
Préparation...                   ###################################################################################################################
      1/3: virtualbox-kernel-5.15.16-desktop-1.mga8
                                 ###################################################################################################################
      2/3: virtualbox-kernel-desktop-latest
                                 ###################################################################################################################
      3/3: virtualbox            ###################################################################################################################
      1/3: désinstallation de virtualbox-kernel-desktop-latest-6.1.30-1.14.mga8.x86_64
                                 ###################################################################################################################
      2/3: désinstallation de virtualbox-6.1.30-1.mga8.x86_64
                                 ###################################################################################################################

-------- Uninstall Beginning --------
Module:  virtualbox
Version: 6.1.30-1.mga8
Kernel:  5.15.16-desktop-1.mga8 (x86_64)
-------------------------------------

Status: Before uninstall, this module version was ACTIVE on this kernel.

vboxdrv.ko.xz:
 - Uninstallation
   - Deleting from: /lib/modules/5.15.16-desktop-1.mga8/dkms-binary/3rdparty/vbox/
 - Original module
   - No original module was found for this module on this kernel.
   - Use the dkms install command to reinstall any previous module version.

vboxnetflt.ko.xz:
 - Uninstallation
   - Deleting from: /lib/modules/5.15.16-desktop-1.mga8/dkms-binary/3rdparty/vbox/
 - Original module
   - No original module was found for this module on this kernel.
   - Use the dkms install command to reinstall any previous module version.

vboxnetadp.ko.xz:
 - Uninstallation
   - Deleting from: /lib/modules/5.15.16-desktop-1.mga8/dkms-binary/3rdparty/vbox/
 - Original module
   - No original module was found for this module on this kernel.
   - Use the dkms install command to reinstall any previous module version.
depmod.....

DKMS: uninstall Completed.
      3/3: désinstallation de virtualbox-kernel-5.15.16-desktop-1.mga8-6.1.30-1.14.mga8.x86_64
                                 ###################################################################################################################

vboxdrv.ko.xz:
 - Installation
   - Installing to /lib/modules/5.15.16-desktop-1.mga8/dkms-binary/3rdparty/vbox/

vboxnetflt.ko.xz:
 - Installation
   - Installing to /lib/modules/5.15.16-desktop-1.mga8/dkms-binary/3rdparty/vbox/

vboxnetadp.ko.xz:
 - Installation
   - Installing to /lib/modules/5.15.16-desktop-1.mga8/dkms-binary/3rdparty/vbox/

depmod.....

DKMS: install Completed.
virtualbox, 6.1.32-1.mga8, 5.15.16-desktop-1.mga8, x86_64: installed-binary from 5.15.16-desktop-1.mga8
+ /usr/sbin/rmmod vboxnetflt
+ /usr/sbin/rmmod vboxnetadp
+ /usr/sbin/rmmod vboxdrv
+ /usr/sbin/modprobe vboxdrv
+ /usr/sbin/modprobe vboxnetflt
+ /usr/sbin/modprobe vboxnetadp
+ :
```

```
TESTS
=====
* Installation of Manjaro KDE and Mageia Cauldron
** PAE/NX selected
** Graphic controler: VMSVGA with 3D acceleration
** Storage: E/S host cache selected
** Guest addition inserted
** Display size adjustment: ok
** Folder sharing: ok
** Clipboard sharing: ok
** Sound: ok
** Video reading with VLC: ok
** USB sharing (webcam and flash drive): Not OK, but I just noticed I have the same issue with 6.1.30...

I get the following error with the webcam (kamoso or cheese): 
(cheese:2340): cheese-WARNING **: 17:20:38.852: Impossible to allocate memory: ../sys/v4l2/gstv4l2src.c(659): gst_v4l2src_decide_allocation (): /GstCameraBin:camerabin/GstWrapperCameraBinSrc:camera_source/GstBin:bin35/GstV4l2Src:v4l2src1:
Buffer pool activation failed

By the way, why is only USB1.1 controller proposed in the configuration, and not the USB2? 
```

CC: (none) => chb0

Comment 9 Thomas Andrews 2022-01-25 19:03:57 CET
(In reply to christian barranco from comment #8)

> 
> By the way, why is only USB1.1 controller proposed in the configuration, and
> not the USB2? 
> ```

You have to download the appropriate extension pack from Adobe and install it to get usb 2 or 3. It's proprietary, and Mageia doesn't have permission to distribute it. I usually get mine from 
https://download.virtualbox.org/virtualbox/ Scroll down to the version you want, and all the downloads are available there.

Also, be sure that any user of VirtualBox is in the vboxusers group.
Comment 10 Dave Hodgins 2022-01-25 19:43:08 CET
Note that the extension pack must be installed on the host, while the guest
additions have to be installed in each guest.

CC: (none) => davidwhodgins

Comment 11 christian barranco 2022-01-25 21:23:23 CET
(In reply to Thomas Andrews from comment #9)
> (In reply to christian barranco from comment #8)
> 
> > 
> > By the way, why is only USB1.1 controller proposed in the configuration, and
> > not the USB2? 
> > ```
> 
> You have to download the appropriate extension pack from Adobe and install
> it to get usb 2 or 3. It's proprietary, and Mageia doesn't have permission
> to distribute it. I usually get mine from 
> https://download.virtualbox.org/virtualbox/ Scroll down to the version you
> want, and all the downloads are available there.
> 
> Also, be sure that any user of VirtualBox is in the vboxusers group.

I have the extension packed installed; I just checked. Weird...
Comment 12 Dave Hodgins 2022-01-25 22:42:39 CET
Is it the 6.1.32 version that's installed? The version must match that of
virtualbox.

https://download.virtualbox.org/virtualbox/6.1.32/Oracle_VM_VirtualBox_Extension_Pack-6.1.32.vbox-extpack
Comment 13 christian barranco 2022-01-26 07:42:03 CET
Hi. 
Yes it was 6.1.32
I reinstalled it and, now, I get usb2 & 3 controller options. 
Cheese and Kamoso don’t crash anymore; but no image yet, despite the webcam is detected. 
Should the guest addition in the vm match 6.1.32 as well? 
I’ll test that later today.
Comment 14 christian barranco 2022-01-26 11:37:51 CET
Hi. Solved. I had to activate the USB3 controller. 

All good for me with this 6.1.32 update.
Comment 15 Morgan Leijström 2022-01-26 13:42:25 CET
Well, you should use a matching guest addition version
Comment 16 Thomas Andrews 2022-01-26 15:45:33 CET
(In reply to Morgan Leijström from comment #15)
> Well, you should use a matching guest addition version

Indeed yes, but it's not as critical as with the extension pack, as long as the guest additions are only a version or so behind. 

If a distro provides the guest additions as a package, like we do, and they haven't sent out that update yet, then the user is probably better off just waiting for that guest distro, rather than trying to update the guest additions from Adobe.
Comment 17 David Walser 2022-01-26 16:33:41 CET
I thought it was a typo the first time you said it, but then you did it again :D

It is Oracle, not Adobe.
Comment 18 Thomas Andrews 2022-01-26 16:43:12 CET
Oops. Guess I'm not as perfect as I'd like people to believe...

This is one of those situations where I'd love to have the ability to edit my own Bugzilla comments...

Sigh.
Comment 19 David Walser 2022-01-26 16:44:34 CET
I'd like that ability too!  Of course the original comments would still live on in infamy in the bugs list archives.
Thomas Backlund 2022-01-26 20:09:15 CET

Keywords: (none) => advisory, validated_update
Whiteboard: (none) => MGA8-64-OK
CC: (none) => sysadmin-bugs

Comment 20 Mageia Robot 2022-01-26 20:52:17 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0038.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.