Bug 32297 - Update request: kernel-linus-6.4.16-3.mga9
Summary: Update request: kernel-linus-6.4.16-3.mga9
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK MGA9-32-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-09-16 15:36 CEST by Thomas Backlund
Modified: 2023-10-22 23:06 CEST (History)
8 users (show)

See Also:
Source RPM: kernel-linus
CVE:
Status comment:


Attachments

Description Thomas Backlund 2023-09-16 15:36:25 CEST Comment hidden (obsolete)
Comment 2 Len Lawrence 2023-09-17 18:50:05 CEST Comment hidden (obsolete)

CC: (none) => tarazed25

Comment 3 Len Lawrence 2023-09-21 17:04:19 CEST Comment hidden (obsolete)
Comment 4 Ulrich Beckmann 2023-09-21 20:00:15 CEST Comment hidden (obsolete)

CC: (none) => bequimao.de

Comment 5 Ulrich Beckmann 2023-09-28 18:50:01 CEST Comment hidden (obsolete)

Whiteboard: (none) => MGA9-64-OK

Comment 6 Morgan Leijström 2023-09-29 16:22:12 CEST Comment hidden (obsolete)

CC: (none) => fri

Comment 7 Marja Van Waes 2023-10-01 23:08:22 CEST Comment hidden (obsolete)

CC: (none) => marja11, sysadmin-bugs

Comment 8 Morgan Leijström 2023-10-02 18:27:52 CEST
Lets do like in Bug 32296: repurpose the bug.

So, please test again, now kernel-linus-6.4.16-1.mga9

Summary: Update request: kernel-linus-6.5.3-1.mga9 => Update request: kernel-linus-6.4.16-1.mga9
Whiteboard: MGA9-64-OK => (none)

Comment 9 Marja Van Waes 2023-10-10 16:07:23 CEST
(In reply to Morgan Leijström from comment #8)
> Lets do like in Bug 32296: repurpose the bug.
> 
> So, please test again, now kernel-linus-6.4.16-1.mga9

Could someone please add a list of (S)RPMs and suggested advisory?
Marja Van Waes 2023-10-12 19:43:25 CEST

Component: RPM Packages => Security
QA Contact: (none) => security

Comment 10 Morgan Leijström 2023-10-12 21:50:54 CEST
Should this -linus- kernel variant get updated to -3
like we did 6.4.16-desktop-3.mga9?

CC: (none) => chb0, ghibomgx

Comment 11 Giuseppe Ghibò 2023-10-12 22:08:01 CEST
(In reply to Morgan Leijström from comment #10)
> Should this -linus- kernel variant get updated to -3
> like we did 6.4.16-desktop-3.mga9?

yep. Coming soon.
Comment 12 Marja Van Waes 2023-10-13 11:33:00 CEST
Can someone please create an advisory with:

Fixed CVEs

Summary line

Description

SRPMs

links to listed CVEs are not needed, our script adds them automatically. Other links about the update are welcome, though (e.g. when a patch was taken from a different distribution)
Comment 13 Morgan Leijström 2023-10-14 18:16:48 CEST
mga9-64 OK here

HW: Intel i7-870, P55 chipset, Nvidia GTX750
SW: Plasma X11, GNOME Wayland

System was running kernel-desktop-6.4.16-3.mga9.x86_64;
 Installed using urpmi:
kernel-linus-6.4.16-3.mga9.x86_64
kernel-linus-devel-6.4.16-3.mga9.x86_64

DKMS built nvidia470 and VirtualBox modules.

suspend-resume works, only tested a few cycles

Some usual desktop apps, thunderbird, firefox incl internet video

VirtualBox: MSW7 guest OK: internet videos, USB2 flashstick, host folder sharing, bidirectional clipboard, drag file from Dolphin to Explorer (the other way do not work and never have, have not investigated), dynamic window resizing.

Interesting function above our -desktop kernels: 
Dolphin shows my floppy device, and it works.
Comment 14 Morgan Leijström 2023-10-14 20:24:01 CEST
mga9-64 OK on my laptop Dell Precision M6300;
CPU: Intel(R) Core(TM)2 Duo CPU  T7500
GPU: G84GLM [Quadro FX 1600M], using kernel modesetting
Wifi: PRO/Wireless 3945ABG [Golan]

Plasma, desktop apps, firefox internet video, suspend-resume

This is with all other updates incl testing; i.e x11 and mesa.
Morgan Leijström 2023-10-15 21:17:23 CEST

Summary: Update request: kernel-linus-6.4.16-1.mga9 => Update request: kernel-linus-6.4.16-3.mga9

Comment 15 katnatek 2023-10-16 04:59:57 CEST
CPU: dual core Intel Pentium Dual T2370 (-MCP-)

Mageia 9 i586 plasma

From bug#32296 Install
cpupower-6.4.16-3.mga9.i586.rpm
kernel-userspace-headers-6.4.16-3.mga9.i586.rpm
libbpf-devel-6.4.16-3.mga9.i586.rpm
libbpf1-6.4.16-3.mga9.i586.rpm

Install
kernel-linus-6.4.16-3.mga9.i586.rpm
kernel-linus-devel-6.4.16-3.mga9.i586.rpm

Reboot, test kernel without flavor
Audio & Video works
Wifi works
Youtube on firefox works
Comment 16 Len Lawrence 2023-10-16 16:58:13 CEST
This is what I found in updates-testing on my preferred mirror:

kernel-linus-6.4.16-3.mga9.x86_64.rpm
kernel-linus-devel-6.4.16-3.mga9.x86_64.rpm
kernel-linus-devel-latest-6.4.16-3.mga9.x86_64.rpm
kernel-linus-doc-6.4.16-3.mga9.noarch.rpm
kernel-linus-latest-6.4.16-3.mga9.x86_64.rpm
kernel-linus-source-6.4.16-3.mga9.noarch.rpm

Installed those via qarepo/MageiaUpdate then added:
cpupower-6.4.16-3.mga9.x86_64.rpm
cpupower-devel-6.4.16-3.mga9.x86_64.rpm
bpftool-6.4.16-3.mga9.x86_64.rpm
lib64bpf-devel-6.4.16-3.mga9.x86_64.rpm
lib64bpf1-6.4.16-3.mga9.x86_64.rpm

Not sure if the latter are needed with kernel linus but they have always
been supplied for the desktop+server kernels.

Rebooted OK.  Mate desktop running normally; firefox, thunderbird, audio, video, bluetooth....
Checked VirtualBox - launched a 32-bit Mageia client and updated it via mageiawelcome.

Mini-pc System: Entroware product: Aura
Intel model: NUC12WSBi7
12-core (4-mt/8-st) 12th Gen Intel Core i7-1260P
Intel Alder Lake-P Integrated Graphics driver: i915
Intel Alder Lake-P PCH CNVi WiFi driver: iwlwifi
Comment 17 Len Lawrence 2023-10-16 17:28:49 CEST
As a rider to comment 16, cpupower can be tested via commands like the following:

$ cpupower --cpu 2-4 frequency-info
analyzing CPU 2:
  driver: intel_pstate
  CPUs which run at the same hardware frequency: 2
  CPUs which need to have their frequency coordinated by software: 2
  maximum transition latency:  Cannot determine or is not supported.
  hardware limits: 400 MHz - 4.70 GHz
  available cpufreq governors: performance powersave
....

Graphics performance can be tested using for example:

$ elementary_perf test
--------------------------------------------------------------------------------
Performance Test Engine: software_x11
--------------------------------------------------------------------------------
1131.28 (fr=299 load=0.05286 tick=298@59.95Hz) | 0.20 Rectangles (Few)
1877.67 (fr=299 load=0.03185 tick=299@59.95Hz) | 0.40 Rectangles (Few) - Solid
279.02 (fr=297 load=0.21288 tick=299@59.95Hz) | 1.00 Rectangles
....

or glmark2.
Comment 18 Nicolas Salguero 2023-10-19 10:13:59 CEST
Hi,

CVE-2023-5178 (Linux NVMe-oF/TCP Driver - UAF in `nvmet_tcp_free_crypto`) was announced here:
https://www.openwall.com/lists/oss-security/2023/10/15/1

Best regards,

Nico.

CC: (none) => nicolas.salguero

Comment 19 Marja Van Waes 2023-10-19 12:16:45 CEST
Giuseppe, can you please add the advisory?

An example of an uploaded kernel-linus advisory, can be found here:
https://svnweb.mageia.org/advisories/32169.adv?revision=14922&view=markup

All that information is needed, except the last line (ID:MGA*) which is created later.
Comment 20 Marja Van Waes 2023-10-19 20:26:43 CEST
Advisory based on the one for bug 32296 added to SVN:

https://svnweb.mageia.org/advisories/32297.adv?revision=15125&view=markup

Please remove the advisory keyword if there is anything wrong with it and tell me what is wrong.

Keywords: (none) => advisory

Comment 21 Morgan Leijström 2023-10-20 18:01:38 CEST
I would say advisory is OK if the one for 32296 is - provided same patches are in, which I do not know how to check.

Whiteboard: (none) => MGA9-64-OK MGA9-32-OK

Comment 22 Giuseppe Ghibò 2023-10-20 18:25:25 CEST
(In reply to Morgan Leijström from comment #21)
> I would say advisory is OK if the one for 32296 is - provided same patches
> are in, which I do not know how to check.

Yep, it has the same extra patchset.

https://svnweb.mageia.org/packages/updates/9/kernel-linus/current/SPECS/kernel-linus.spec?r1=1992540&r2=1992598

https://svnweb.mageia.org/packages/updates/9/kernel-linus/current/SPECS/kernel-linus.spec?r1=1992599&r2=1995803
Comment 23 Morgan Leijström 2023-10-20 19:04:59 CEST
Thanks
This is good to go then :)

Keywords: (none) => validated_update

Comment 24 Mageia Robot 2023-10-22 23:06:41 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0296.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.