Bug 31423 - phoronix-test-suite new security issue CVE-2022-40704
Summary: phoronix-test-suite new security issue CVE-2022-40704
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-01-17 23:48 CET by David Walser
Modified: 2023-01-24 09:00 CET (History)
5 users (show)

See Also:
Source RPM: phoronix-test-suite-10.8.4-1.mga9.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2023-01-17 23:48:33 CET
Fedora has issued an advisory on January 12:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/ETFF53AECMDP6PTNUVVCOODN3HMOETUU/

Mageia 8 is also affected.
David Walser 2023-01-17 23:48:55 CET

Status comment: (none) => Patches available from upstream and Fedora
Whiteboard: (none) => MGA8TOO

Comment 1 David GEIGER 2023-01-18 16:54:11 CET
Done for both Cauldron and mga8!

CC: (none) => geiger.david68210

Comment 2 David Walser 2023-01-18 20:59:05 CET
phoronix-test-suite-10.8.2-1.1.mga8

from phoronix-test-suite-10.8.2-1.1.mga8.src.rpm

Status comment: Patches available from upstream and Fedora => (none)
Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8
Assignee: bugsquad => qa-bugs

Comment 3 Herman Viaene 2023-01-20 17:36:08 CET
MGA8-64 MATE on Acer Aspire 5253
No installation issues.
Ref bug 30025 for testing:
$ phoronix-test-suite install git/x265

Updated OpenBenchmarking.org Repository Index
pts: 511 Distinct Tests, 2172 Test Versions, 56 Suites
Available Changes From 13 February 2022 To 20 January
Updated Test:   pts/ai-benchmark        v1.0.2  AI Benchmark Alpha                  
Updated Test:   pts/aircrack-ng         v1.3.0  Aircrack-ng                         
Updated Test:   pts/aom-av1             v3.5.0  AOM AV1                             
Updated Test:   pts/apache              v2.0.1  Apache HTTP Server                  
Updated Test:   pts/astcenc             v1.4.0  ASTC Encoder                        
Updated Test:   pts/avifenc             v1.3.0  libavif avifenc                     
Updated Test:   pts/batman-knight       v1.0.1  Batman: Arkham Knight    
and a lot more till at the end
Complete!
    To Install:    git/x265-1.1.0

    Determining File Requirements ...........................................................................
    Searching Download Caches ...............................................................................

    1 Test To Install
        1 File To Download [646MB]
        2600MB Of Disk Space Is Needed
        3 Minutes, 16 Seconds Estimated Install Time

    git/x265-1.1.0:
        Test Installation 1 of 1
        1 File Needed [646 MB]
        Downloading: Bosphorus_1920x1080_120fps_420_8bit_YUV_Y4M.7z                                   [646MB]
        Downloading .........................................................................................
        Approximate Install Size: 2600 MB
        Estimated Install Time: 3 Minutes, 16 Seconds
        Installing Test @ 15:52:58

$ phoronix-test-suite run git/x265


Phoronix Test Suite v10.8.2
System Information


  PROCESSOR:              AMD C-50 @ 1.00GHz
    Core Count:           2                      
    Extensions:           SSE 4a                 
    Cache Size:           512 MB                 
    Microcode:            0x5000029              
    Core Family:          Bobcat                 
    Scaling Driver:       acpi-cpufreq schedutil 

  GRAPHICS:               AMD Radeon HD 6250 256MB
    Frequency:            276MHz                        
    OpenGL:               3.3 Mesa 21.3.8 (LLVM 11.0.1) 
    Screen:               1366x768                      

and more settings till the tests start
x265 Git:
    git/x265-1.1.0
    Test 1 of 1
    Estimated Trial Run Count:    3                     
    Estimated Time To Completion: 5 Minutes [16:13 CET] 
        Started Run 1 @ 16:09:20
        Started Run 2 @ 16:34:23
        Started Run 3 @ 16:59:04

    H.265 1080p Video Encoding:
        0.4
        0.41
        0.4

    Average: 0.40 Frames Per Second
    Deviation: 1.43%

    Comparison of 111 OpenBenchmarking.org samples since 8 March 2019 to 3 December; median result: 25.65 Frames Per Second. Box plot of samples:
    [ |--*---------########################!############################-----------*-----------------------|    ]
         ^ ARMv8 Cortex-A72: 3.11                     AMD Ryzen 5 PRO 4650G: 51.54 ^

On this old laptop it takes ages to complete, but itg apparently does without failure, so OK for me.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => herman.viaene

Comment 4 Thomas Andrews 2023-01-21 14:05:29 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2023-01-24 01:29:14 CET

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 5 Mageia Robot 2023-01-24 09:00:47 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0022.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.