Advertise with Googlier.com Mageia Advisories for package fglrx https://advisories.mageia.org Mageia Advisories for package fglrx en MGAA-2016-0089 - Updated fglrx packages fix a GPL violation and add support for newer kernels https://advisories.mageia.org/MGAA-2016-0089.html MGAA-2016-0089 Thu, 09 Jun 2016 12:45:26 GMT 2016-06-09T12:38:15Z bugfix Publication date: 09 Jun 2016<br /> Type: bugfix<br /> Affected Mageia releases : <a href="5.html">5</a> <br /> <h2>Description</h2> <pre>Updated fglrx driver fixes GPL violation It's been found that shipping prebuilt proprietary kernel modules is in violation of the GPL license. Since Mageia.org is pro open source we adjust the way we provide support for propritetary drivers. In order to comply with GPL, this update switches to dkms source based setup that builds the needed modules at kernel / driver install time. This update also adds support for kernel 4.4 series. </pre> <h2>References</h2> <ul> <li><a href="https://bugs.mageia.org/show_bug.cgi?id=18525">https://bugs.mageia.org/show_bug.cgi?id=18525</a></li> </ul> <h2>SRPMS</h2> <h3>5/nonfree</h3> <ul> <li>fglrx-15.302-4.mga5.nonfree</li> <li>kmod-fglrx-15.302-10.mga5.nonfree</li> </ul> MGAA-2016-0027 - Updated fglrx packages fix kernel 4.1 support https://advisories.mageia.org/MGAA-2016-0027.html MGAA-2016-0027 Wed, 17 Feb 2016 19:37:22 GMT 2016-02-17T19:35:52Z bugfix Publication date: 17 Feb 2016<br /> Type: bugfix<br /> Affected Mageia releases : <a href="5.html">5</a> <br /> <h2>Description</h2> <pre>Updated Amd fglrx drivers This update provides upstream Amd Catalyst / Crimson drivers that provides official support for kernel 4.1 series and newer ones. They also add support for more hw, fixes several game related bugs and some stuttering and screen corruption bugs </pre> <h2>References</h2> <ul> <li><a href="https://bugs.mageia.org/show_bug.cgi?id=17601">https://bugs.mageia.org/show_bug.cgi?id=17601</a></li> </ul> <h2>SRPMS</h2> <h3>5/nonfree</h3> <ul> <li>fglrx-15.302-1.mga5.nonfree</li> <li>kmod-fglrx-15.302-1.mga5.nonfree</li> </ul> MGAA-2015-0095 - Updated ldetect-lst, fglrx packages adds official support for kernel 3.19 https://advisories.mageia.org/MGAA-2015-0095.html MGAA-2015-0095 Fri, 21 Aug 2015 20:17:06 GMT 2015-08-21T20:11:50Z bugfix Publication date: 21 Aug 2015<br /> Type: bugfix<br /> Affected Mageia releases : <a href="5.html">5</a> <br /> <h2>Description</h2> <pre>This update provides the fglrx Catalyst 15.7 release that adds official support for 3.19 series kernels, adds support for more GPUs and improves performance. </pre> <h2>References</h2> <ul> <li><a href="https://bugs.mageia.org/show_bug.cgi?id=16439">https://bugs.mageia.org/show_bug.cgi?id=16439</a></li> <li><a href="http://support.amd.com/en-us/download/desktop?os=Linux+x86">http://support.amd.com/en-us/download/desktop?os=Linux+x86</a></li> </ul> <h2>SRPMS</h2> <h3>5/core</h3> <ul> <li>ldetect-lst-0.1.346-1.mga5</li> </ul> <h3>5/nonfree</h3> <ul> <li>fglrx-15.200.1046-1.1.mga5.nonfree</li> <li>kmod-fglrx-15.200.1046-1.1.mga5.nonfree</li> </ul> MGAA-2014-0127 - Updated fglrx packages provide support for additional hardware https://advisories.mageia.org/MGAA-2014-0127.html MGAA-2014-0127 Wed, 18 Jun 2014 19:00:52 GMT 2014-06-18T19:00:48Z bugfix Publication date: 18 Jun 2014<br /> Type: bugfix<br /> Affected Mageia releases : <a href="4.html">4</a> <br /> <h2>Description</h2> <pre>This update provides an update to AMD Catalyst 14.4 wich fixes several bugs and provides support for additional hardware. </pre> <h2>References</h2> <ul> <li><a href="http://support.amd.com/en-us/kb-articles/Pages/AMDCatalyst14-4LINReleaseNotes.aspx">http://support.amd.com/en-us/kb-articles/Pages/AMDCatalyst14-4LINReleaseNotes.aspx</a></li> <li><a href="https://bugs.mageia.org/show_bug.cgi?id=13451">https://bugs.mageia.org/show_bug.cgi?id=13451</a></li> </ul> <h2>SRPMS</h2> <h3>4/core</h3> <ul> <li>ldetect-lst-0.1.334-1.mga4</li> </ul> <h3>4/nonfree</h3> <ul> <li>fglrx-14.010.1006-1.mga4.nonfree</li> <li>kmod-fglrx-14.010.1006-2.mga4.nonfree</li> </ul> MGASA-2014-0038 - Updated kernel package fixes one critical and a few other security issues https://advisories.mageia.org/MGASA-2014-0038.html MGASA-2014-0038 Sat, 08 Feb 2014 19:01:59 GMT 2014-02-08T19:01:52Z security Publication date: 08 Feb 2014<br /> Type: security<br /> Affected Mageia releases : <a href="3.html">3</a> <br /> CVE: <a href="CVE-2013-4579.html">CVE-2013-4579</a> , <a href="CVE-2014-0038.html">CVE-2014-0038</a> , <a href="CVE-2014-1438.html">CVE-2014-1438</a> , <a href="CVE-2014-1446.html">CVE-2014-1446</a> , <a href="CVE-2014-1690.html">CVE-2014-1690</a> <h2>Description</h2> <pre>This kernel update provides an update to the 3.10 longterm branch, currently 3.10.28 and fixes the following security issues: The ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12 uses a BSSID masking approach to determine the set of MAC addresses on which a Wi-Fi device is listening, which allows remote attackers to discover the original MAC address after spoofing by sending a series of packets to MAC addresses with certain bit manipulations. (CVE-2013-4579) Pageexec reported a bug in the Linux kernel's recvmmsg syscall when called from code using the x32 ABI. An unprivileged local user could exploit this flaw to cause a denial of service (system crash) or gain administrator privileges (CVE-2014-0038) Faults during task-switch due to unhandled FPU-exceptions allow to kill processes at random on all affected kernels, resulting in local DOS in the end. One some architectures, privilege escalation under non-common circumstances is possible. (CVE-2014-1438) The hamradio yam_ioctl() code fails to initialise the cmd field of the struct yamdrv_ioctl_cfg leading to a 4-byte info leak. (CVE-2014-1446) Linux kernel built with the NetFilter Connection Tracking(NF_CONNTRACK) support for IRC protocol(NF_NAT_IRC), is vulnerable to an information leakage flaw. It could occur when communicating over direct client-to-client IRC connection(/dcc) via a NAT-ed network. Kernel attempts to mangle IRC TCP packet's content, wherein an uninitialised 'buffer' object is copied to a socket buffer and sent over to the other end of a connection. (CVE-2014-1690) It also fixes an issue where some laptops are forced to use vesa driver & No ACPI (mga#6077) For other upstream fixes, see the referenced changelogs. The proprietary fglrx driver has also been updated from Catalyst 13.11-beta6 to Catalyst 13.12 official driver. </pre> <h2>References</h2> <ul> <li><a href="https://bugs.mageia.org/show_bug.cgi?id=6077">https://bugs.mageia.org/show_bug.cgi?id=6077</a></li> <li><a href="https://bugs.mageia.org/show_bug.cgi?id=12517">https://bugs.mageia.org/show_bug.cgi?id=12517</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.25">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.25</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.26">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.26</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.27">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.27</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.28">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.28</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-4579">https://www.cve.org/CVERecord?id=CVE-2013-4579</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2014-0038">https://www.cve.org/CVERecord?id=CVE-2014-0038</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2014-1438">https://www.cve.org/CVERecord?id=CVE-2014-1438</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2014-1446">https://www.cve.org/CVERecord?id=CVE-2014-1446</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2014-1690">https://www.cve.org/CVERecord?id=CVE-2014-1690</a></li> </ul> <h2>SRPMS</h2> <h3>3/core</h3> <ul> <li>kernel-3.10.28-1.mga3</li> <li>kernel-userspace-headers-3.10.28-1.mga3</li> <li>kmod-vboxadditions-4.2.16-7.mga3</li> <li>kmod-virtualbox-4.2.16-7.mga3</li> <li>kmod-xtables-addons-2.3-11.mga3</li> </ul> <h3>3/nonfree</h3> <ul> <li>fglrx-13.251-1.mga3.nonfree</li> <li>kmod-broadcom-wl-6.30.223.141-10.mga3.nonfree</li> <li>kmod-fglrx-13.251-3.mga3.nonfree</li> <li>kmod-nvidia173-173.14.38-27.mga3.nonfree</li> <li>kmod-nvidia304-304.108-12.mga3.nonfree</li> <li>kmod-nvidia-current-319.60-11.mga3.nonfree</li> </ul> MGASA-2013-0371 - Updated kernel and related packages fix security vulnerabilities https://advisories.mageia.org/MGASA-2013-0371.html MGASA-2013-0371 Tue, 17 Dec 2013 22:38:56 GMT 2013-12-17T22:58:18Z security Publication date: 17 Dec 2013<br /> Type: security<br /> Affected Mageia releases : <a href="3.html">3</a> <br /> CVE: <a href="CVE-2013-0343.html">CVE-2013-0343</a> , <a href="CVE-2013-1059.html">CVE-2013-1059</a> , <a href="CVE-2013-2140.html">CVE-2013-2140</a> , <a href="CVE-2013-2147.html">CVE-2013-2147</a> , <a href="CVE-2013-2851.html">CVE-2013-2851</a> , <a href="CVE-2013-2888.html">CVE-2013-2888</a> , <a href="CVE-2013-2889.html">CVE-2013-2889</a> , <a href="CVE-2013-2891.html">CVE-2013-2891</a> , <a href="CVE-2013-2892.html">CVE-2013-2892</a> , <a href="CVE-2013-2893.html">CVE-2013-2893</a> , <a href="CVE-2013-2894.html">CVE-2013-2894</a> , <a href="CVE-2013-2895.html">CVE-2013-2895</a> , <a href="CVE-2013-2896.html">CVE-2013-2896</a> , <a href="CVE-2013-2897.html">CVE-2013-2897</a> , <a href="CVE-2013-2898.html">CVE-2013-2898</a> , <a href="CVE-2013-2899.html">CVE-2013-2899</a> , <a href="CVE-2013-2929.html">CVE-2013-2929</a> , <a href="CVE-2013-2930.html">CVE-2013-2930</a> , <a href="CVE-2013-4162.html">CVE-2013-4162</a> , <a href="CVE-2013-4163.html">CVE-2013-4163</a> , <a href="CVE-2013-4254.html">CVE-2013-4254</a> , <a href="CVE-2013-4299.html">CVE-2013-4299</a> , <a href="CVE-2013-4348.html">CVE-2013-4348</a> , <a href="CVE-2013-4350.html">CVE-2013-4350</a> , <a href="CVE-2013-4387.html">CVE-2013-4387</a> , <a href="CVE-2013-4470.html">CVE-2013-4470</a> , <a href="CVE-2013-4513.html">CVE-2013-4513</a> , <a href="CVE-2013-4587.html">CVE-2013-4587</a> , <a href="CVE-2013-6367.html">CVE-2013-6367</a> , <a href="CVE-2013-6368.html">CVE-2013-6368</a> , <a href="CVE-2013-6376.html">CVE-2013-6376</a> , <a href="CVE-2013-6378.html">CVE-2013-6378</a> , <a href="CVE-2013-6380.html">CVE-2013-6380</a> , <a href="CVE-2013-6381.html">CVE-2013-6381</a> , <a href="CVE-2013-6382.html">CVE-2013-6382</a> , <a href="CVE-2013-6383.html">CVE-2013-6383</a> <h2>Description</h2> <pre>This kernel update provides an update to the 3.10 longterm branch, currently 3.10.24 and fixes the following security issues: The ipv6_create_tempaddr function in net/ipv6/addrconf.c in the Linux kernel through 3.10 does not properly handle problems with the generation of IPv6 temporary addresses, which allows remote attackers to cause a denial of service (excessive retries and address-generation outage), and consequently obtain sensitive information, via ICMPv6 Router Advertisement (RA) messages. (CVE-2013-0343) net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an auth_reply message that triggers an attempted build_request operation. (CVE-2013-1059) The dispatch_discard_io function in drivers/block/xen-blkback/blkback.c in the Xen blkback implementation in the Linux kernel before 3.10.5 allows guest OS users to cause a denial of service (data loss) via filesystem write operations on a read-only disk that supports the (1) BLKIF_OP_DISCARD (aka discard or TRIM) or (2) SCSI UNMAP feature. (CVE-2013-2140) The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3.9.4 do not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory via (1) a crafted IDAGETPCIINFO command for a /dev/ida device, related to the ida_locked_ioctl function in drivers/block/cpqarray.c or (2) a crafted CCISS_PASSTHRU32 command for a /dev/cciss device, related to the cciss_ioctl32_passthru function in drivers/block/cciss.c. (CVE-2013-2147) Format string vulnerability in the register_disk function in block/genhd.c in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and writing format string specifiers to /sys/module/md_mod/parameters/new_array in order to create a crafted /dev/md device name. (CVE-2013-2851) Multiple array index errors in drivers/hid/hid-core.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11 allow physically proximate attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted device that provides an invalid Report ID (CVE-2013-2888). drivers/hid/hid-zpff.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_ZEROPLUS is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device (CVE-2013-2889). drivers/hid/hid-steelseries.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_STEELSERIES is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device. (CVE-2013-2891) drivers/hid/hid-pl.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_PANTHERLORD is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device (CVE-2013-2892). The Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_LOGITECH_FF, CONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device, related to (1) drivers/hid/hid-lgff.c, (2) drivers/hid/hid-lg3ff.c, and (3) drivers/hid/hid-lg4ff.c (CVE-2013-2893). drivers/hid/hid-lenovo-tpkbd.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_LENOVO_TPKBD is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device. (CVE-2013-2894) drivers/hid/hid-logitech-dj.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_LOGITECH_DJ is enabled, allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) or obtain sensitive information from kernel memory via a crafted device (CVE-2013-2895). drivers/hid/hid-ntrig.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_NTRIG is enabled, allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) via a crafted device (CVE-2013-2896). Multiple array index errors in drivers/hid/hid-multitouch.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_MULTITOUCH is enabled, allow physically proximate attackers to cause a denial of service (heap memory corruption, or NULL pointer dereference and OOPS) via a crafted device (CVE-2013-2897). drivers/hid/hid-sensor-hub.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_SENSOR_HUB is enabled, allows physically proximate attackers to obtain sensitive information from kernel memory via a crafted device. (CVE-2013-2898) drivers/hid/hid-picolcd_core.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_PICOLCD is enabled, allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) via a crafted device (CVE-2013-2899). The Linux kernel before 3.12.2 does not properly use the get_dumpable function, which allows local users to bypass intended ptrace restrictions or obtain sensitive information from IA64 scratch registers via a crafted application, related to kernel/ptrace.c and arch/ia64/include/asm/processor.h (CVE-2013-2929) The perf_trace_event_perm function in kernel/trace/trace_event_perf.c in the Linux kernel before 3.12.2 does not properly restrict access to the perf subsystem, which allows local users to enable function tracing via a crafted application. (CVE-2013-2930) The udp_v6_push_pending_frames function in net/ipv6/udp.c in the IPv6 implementation in the Linux kernel through 3.10.3 makes an incorrect function call for pending data, which allows local users to cause a denial of service (BUG and system crash) via a crafted application that uses the UDP_CORK option in a setsockopt system call (CVE-2013-4162). The ip6_append_data_mtu function in net/ipv6/ip6_output.c in the IPv6 implementation in the Linux kernel through 3.10.3 does not properly maintain information about whether the IPV6_MTU setsockopt option had been specified, which allows local users to cause a denial of service (BUG and system crash) via a crafted application that uses the UDP_CORK option in a setsockopt system call (CVE-2013-4163). The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel before 3.10.8 on the ARM platform allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by adding a hardware event to an event group led by a software event (CVE-2013-4254) Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel through 3.11.6 allows remote authenticated users to obtain sensitive information or modify data via a crafted mapping to a snapshot block device. (CVE-2013-4299) The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of service (infinite loop) via a small value in the IHL field of a packet with IPIP encapsulation (CVE-2013-4348). The IPv6 SCTP implementation in net/sctp/ipv6.c in the Linux kernel through 3.11.1 uses data structures and function calls that do not trigger an intended configuration of IPsec encryption, which allows remote attackers to obtain sensitive information by sniffing the network (CVE-2013-4350). net/ipv6/ip6_output.c in the Linux kernel through 3.11.4 does not properly determine the need for UDP Fragmentation Offload (UFO) processing of small packets after the UFO queueing of a large packet, which allows remote attackers to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via network traffic that triggers a large response packet (CVE-2013-4387). The Linux kernel before 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly initialize certain data structures, which allows local users to cause a denial of service (memory corruption and system crash) or possibly gain privileges via a crafted application that uses the UDP_CORK option in a setsockopt system call and sends both short and long packets, related to the ip_ufo_append_data function in net/ipv4/ip_output.c and the ip6_ufo_append_data function in net/ipv6/ip6_output.c (CVE-2013-4470). Buffer overflow in the oz_cdev_write function in drivers/staging/ozwpan/ozcdev.c in the Linux kernel before 3.12 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted write operation. (CVE-2013-4513) Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges via a large id value (CVE-2013-4587) The apic_get_tmcct function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via crafted modifications of the TMICT value. (CVE-2013-6367) The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC synchronization operation involving a page-end address. (CVE-2013-6368) The recalculate_apic_map function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial of service (host OS crash) via a crafted ICR write operation in x2apic mode. (CVE-2013-6376) The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service (OOPS) by leveraging root privileges for a zero-length write operation. (CVE-2013-6378) The aac_send_raw_srb function in drivers/scsi/aacraid/commctrl.c in the Linux kernel through 3.12.1 does not properly validate a certain size value, which allows local users to cause a denial of service (invalid pointer dereference) or possibly have unspecified other impact via an FSACTL_SEND_RAW_SRB ioctl call that triggers a crafted SRB command. (CVE-2013-6380) Buffer overflow in the qeth_snmp_command function in drivers/s390/net/qeth_core_main.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service or possibly have unspecified other impact via an SNMP ioctl call with a length value that is incompatible with the command-buffer size. (CVE-2013-6381) Multiple buffer underflows in the XFS implementation in the Linux kernel through 3.12.1 allow local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for a (1) XFS_IOC_ATTRLIST_BY_HANDLE or (2) XFS_IOC_ATTRLIST_BY_HANDLE_32 ioctl call with a crafted length value, related to the xfs_attrlist_by_handle function in fs/xfs/xfs_ioctl.c and the xfs_compat_attrlist_by_handle function in fs/xfs/xfs_ioctl32.c. (CVE-2013-6382) The aac_compat_ioctl function in drivers/scsi/aacraid/linit.c in the Linux kernel before 3.11.8 does not require the CAP_SYS_RAWIO capability, which allows local users to bypass intended access restrictions via a crafted ioctl call. (CVE-2013-6383) Other fixes: - xfs: add capability check to free eofblocks ioctl (CVE pending) - cpufreq: ondemand: Change the calculation of target frequency - ndiswrapper is updated to 1.59 Also with this update we provide updated graphical drivers, firmwares, tools and apps to provide better support for the new kernel (see the referenced srpms list for all packages) For other -stable fixes, read the referenced changelogs. </pre> <h2>References</h2> <ul> <li><a href="https://bugs.mageia.org/show_bug.cgi?id=11463">https://bugs.mageia.org/show_bug.cgi?id=11463</a></li> <li><a href="http://kernelnewbies.org/Linux_3.9">http://kernelnewbies.org/Linux_3.9</a></li> <li><a href="http://kernelnewbies.org/Linux_3.10">http://kernelnewbies.org/Linux_3.10</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.1">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.1</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.2">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.2</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.3">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.3</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.4">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.4</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.5">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.5</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.6">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.6</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.7">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.7</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.8">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.8</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.9">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.9</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.10">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.10</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.11">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.11</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.12">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.12</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.13">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.13</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.14">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.14</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.15">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.15</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.16">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.16</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.17">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.17</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.18">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.18</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.19">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.19</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.20">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.20</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.21">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.21</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.22">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.22</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.23">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.23</a></li> <li><a href="https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.24">https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.24</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-0343">https://www.cve.org/CVERecord?id=CVE-2013-0343</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-1059">https://www.cve.org/CVERecord?id=CVE-2013-1059</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2140">https://www.cve.org/CVERecord?id=CVE-2013-2140</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2147">https://www.cve.org/CVERecord?id=CVE-2013-2147</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2851">https://www.cve.org/CVERecord?id=CVE-2013-2851</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2888">https://www.cve.org/CVERecord?id=CVE-2013-2888</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2889">https://www.cve.org/CVERecord?id=CVE-2013-2889</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2891">https://www.cve.org/CVERecord?id=CVE-2013-2891</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2892">https://www.cve.org/CVERecord?id=CVE-2013-2892</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2893">https://www.cve.org/CVERecord?id=CVE-2013-2893</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2894">https://www.cve.org/CVERecord?id=CVE-2013-2894</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2895">https://www.cve.org/CVERecord?id=CVE-2013-2895</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2896">https://www.cve.org/CVERecord?id=CVE-2013-2896</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2897">https://www.cve.org/CVERecord?id=CVE-2013-2897</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2898">https://www.cve.org/CVERecord?id=CVE-2013-2898</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2899">https://www.cve.org/CVERecord?id=CVE-2013-2899</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2929">https://www.cve.org/CVERecord?id=CVE-2013-2929</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2930">https://www.cve.org/CVERecord?id=CVE-2013-2930</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-4162">https://www.cve.org/CVERecord?id=CVE-2013-4162</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-4163">https://www.cve.org/CVERecord?id=CVE-2013-4163</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-4254">https://www.cve.org/CVERecord?id=CVE-2013-4254</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-4299">https://www.cve.org/CVERecord?id=CVE-2013-4299</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-4348">https://www.cve.org/CVERecord?id=CVE-2013-4348</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-4350">https://www.cve.org/CVERecord?id=CVE-2013-4350</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-4387">https://www.cve.org/CVERecord?id=CVE-2013-4387</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-4470">https://www.cve.org/CVERecord?id=CVE-2013-4470</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-4513">https://www.cve.org/CVERecord?id=CVE-2013-4513</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-4587">https://www.cve.org/CVERecord?id=CVE-2013-4587</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-6367">https://www.cve.org/CVERecord?id=CVE-2013-6367</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-6368">https://www.cve.org/CVERecord?id=CVE-2013-6368</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-6376">https://www.cve.org/CVERecord?id=CVE-2013-6376</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-6378">https://www.cve.org/CVERecord?id=CVE-2013-6378</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-6380">https://www.cve.org/CVERecord?id=CVE-2013-6380</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-6381">https://www.cve.org/CVERecord?id=CVE-2013-6381</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-6382">https://www.cve.org/CVERecord?id=CVE-2013-6382</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-6383">https://www.cve.org/CVERecord?id=CVE-2013-6383</a></li> </ul> <h2>SRPMS</h2> <h3>3/core</h3> <ul> <li>btrfs-progs-0.20-0.rc1.20130705.2.mga3</li> <li>drakxtools-15.54.1-3.mga3</li> <li>kernel-3.10.24-2.mga3</li> <li>kernel-firmware-20130624-1.mga3</li> <li>kernel-userspace-headers-3.10.24-2.mga3</li> <li>kmod-vboxadditions-4.2.16-4.mga3</li> <li>kmod-virtualbox-4.2.16-4.mga3</li> <li>kmod-xtables-addons-2.3-8.mga3</li> <li>ldetect-lst-0.1.330-1.mga3</li> <li>libdrm-2.4.46-1.mga3</li> <li>mesa-9.1.7-1.1.mga3</li> <li>x11-driver-video-ati-7.2.0-1.mga3</li> <li>x11-driver-video-intel-2.21.15-1.mga3</li> <li>x11-driver-video-nouveau-1.0.9-1.mga3</li> <li>xtables-addons-2.3-2.mga3</li> </ul> <h3>3/nonfree</h3> <ul> <li>broadcom-wl-6.30.223.141-1.mga3.nonfree</li> <li>fglrx-13.250.18-0.1.mga3.nonfree</li> <li>kernel-firmware-nonfree-20130624-1.mga3.nonfree</li> <li>kmod-broadcom-wl-6.30.223.141-7.mga3.nonfree</li> <li>kmod-fglrx-13.250.18-5.mga3.nonfree</li> <li>kmod-nvidia173-173.14.38-24.mga3.nonfree</li> <li>kmod-nvidia304-304.108-9.mga3.nonfree</li> <li>kmod-nvidia-current-319.60-8.mga3.nonfree</li> <li>nvidia173-173.14.38-1.mga3.nonfree</li> <li>nvidia304-304.108-2.mga3.nonfree</li> <li>nvidia-current-319.60-1.mga3.nonfree</li> <li>radeon-firmware-20130626-2.mga3.nonfree</li> </ul> <h3>3/tainted</h3> <ul> <li>mesa-9.1.7-1.1.mga3.tainted</li> </ul> MGASA-2013-0204 - Updated kernel packages fix multiple security vulnerabilities https://advisories.mageia.org/MGASA-2013-0204.html MGASA-2013-0204 Tue, 09 Jul 2013 17:56:42 GMT 2013-07-09T17:55:40Z security Publication date: 09 Jul 2013<br /> Type: security<br /> Affected Mageia releases : <a href="3.html">3</a> <br /> CVE: <a href="CVE-2013-0231.html">CVE-2013-0231</a> , <a href="CVE-2013-2232.html">CVE-2013-2232</a> , <a href="CVE-2013-2234.html">CVE-2013-2234</a> , <a href="CVE-2013-2237.html">CVE-2013-2237</a> , <a href="CVE-2013-2850.html">CVE-2013-2850</a> , <a href="CVE-2013-2852.html">CVE-2013-2852</a> <h2>Description</h2> <pre>This kernel update provides the extended stable 3.8.13.4 kernel and fixes the follwing security issues: The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi.c) in Xen for the Linux kernel 2.6.18 and 3.8 allows guest OS users with PCI device access to cause a denial of service via a large number of kernel log messages. (CVE-2013-0231 / XSA-43) ipv6: ip6_sk_dst_check() must not assume ipv6 dst It's possible to use AF_INET6 sockets and to connect to an IPv4 destination. After this, socket dst cache is a pointer to a rtable, not rt6_info. This bug can be exploited by local non-root users to trigger various corruptions/crashes (CVE-2013-2232) af_key: fix info leaks in notify messages key_notify_sa_flush() and key_notify_policy_flush() miss to initialize the sadb_msg_reserved member of the broadcasted message and thereby leak 2 bytes of heap memory to listeners (CVE-2013-2234) af_key: initialize satype in key_notify_policy_flush() key_notify_policy_flush() miss to nitialize the sadb_msg_satype member of the broadcasted message and thereby leak heap memory to listeners (CVE-2013-2237) Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters.c in the iSCSI target subsystem in the Linux kernel through 3.9.4 allows remote attackers to cause a denial of service (memory corruption and OOPS) or possibly execute arbitrary code via a long key that is not properly handled during construction of an error-response packet. A reproduction case requires patching open-iscsi to send overly large keys. Performing discovery in a loop will Oops the remote server. (CVE-2013-2850) Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format string specifiers in an fwpostfix modprobe parameter, leading to improper construction of an error message. (CVE-2013-2852) Other fixes: - Fix up alx AR8161 breakage (mga #10079) - bcma: add support for BCM43142 (mga#9378, mga#10611) - net/tg3: Avoid delay during MMIO access - re-add aufs support (mga#8314) - enable support for more touchscreens - iommu/vt-d: add quirk for broken interrupt remapping on 55XX chipsets - rtlwifi: rtl8723ae: Fix typo in firmware names - rtlwifi: rtl8192cu: Fix problem in connecting to WEP or WPA(1) networks - md/raid10: fix two bugs affecting RAID10 reshape - crypto: algboss - Hold ref count on larval - perf: Disable monitoring on setuid processes for regular users - netfilter: nf_conntrack_ipv6: Plug sk_buff leak in fragment handling - enable X86_X2APIC, X86_REROUTE_FOR_BROKEN_BOOT_IRQS, FHANDLE - disable COMPAT_VDSO (not needed since glibc-2.3.3) - conflict too old plymouth to make cleaner upgrades (mga #10128) (fixes the errata for online upgraders) For other fixes in the extended stable update, see the referenced shortlog </pre> <h2>References</h2> <ul> <li><a href="https://bugs.mageia.org/show_bug.cgi?id=10697">https://bugs.mageia.org/show_bug.cgi?id=10697</a></li> <li><a href="http://kernel.ubuntu.com/git?p=ubuntu/linux.git;h=refs/heads/linux-3.8.y;a=shortlog">http://kernel.ubuntu.com/git?p=ubuntu/linux.git;h=refs/heads/linux-3.8.y;a=shortlog</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-0231">https://www.cve.org/CVERecord?id=CVE-2013-0231</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2232">https://www.cve.org/CVERecord?id=CVE-2013-2232</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2234">https://www.cve.org/CVERecord?id=CVE-2013-2234</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2237">https://www.cve.org/CVERecord?id=CVE-2013-2237</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2850">https://www.cve.org/CVERecord?id=CVE-2013-2850</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2013-2852">https://www.cve.org/CVERecord?id=CVE-2013-2852</a></li> </ul> <h2>SRPMS</h2> <h3>3/core</h3> <ul> <li>kernel-3.8.13.4-1.mga3</li> <li>kernel-userspace-headers-3.8.13.4-1.mga3</li> <li>kmod-vboxadditions-4.2.12-14.mga3</li> <li>kmod-virtualbox-4.2.12-14.mga3</li> <li>kmod-xtables-addons-2.1-31.mga3</li> </ul> <h3>3/nonfree</h3> <ul> <li>fglrx-12.104-3.mga3.nonfree</li> <li>kmod-broadcom-wl-5.100.82.112-83.mga3.nonfree</li> <li>kmod-fglrx-12.104-10.mga3.nonfree</li> <li>kmod-nvidia173-173.14.37-16.mga3.nonfree</li> <li>kmod-nvidia304-304.88-15.mga3.nonfree</li> <li>kmod-nvidia-current-319.17-7.mga3.nonfree</li> </ul>