Bug 1578909
Summary: | oVirt Node 4.2.3 respin needed including CVE fixes | ||
---|---|---|---|
Product: | [oVirt] ovirt-node | Reporter: | Sandro Bonazzola <sbonazzo> |
Component: | Build | Assignee: | Sandro Bonazzola <sbonazzo> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | cshao <cshao> |
Severity: | urgent | Docs Contact: | |
Priority: | urgent | ||
Version: | 4.2 | CC: | bugs, cshao, dmoppert, huzhao, jiaczhan, qiyuan, rob, sbonazzo, weiwang, yaniwang, ycui, yzhao |
Target Milestone: | ovirt-4.2.3 | Flags: | rule-engine:
ovirt-4.2+
cshao: testing_ack+ |
Target Release: | 4.2 | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2018-05-25 12:05:20 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | Node | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Sandro Bonazzola
2018-05-16 15:17:58 UTC
There are 45 packages being built right now including first batch update of RHEL 7.5. Worth to wait for them as well. Still waiting for CentOS builds to finish. Any chance the new version will include fix for this? https://bugzilla.redhat.com/show_bug.cgi?id=1496517 (In reply to Rob Sanders from comment #3) > Any chance the new version will include fix for this? > > https://bugzilla.redhat.com/show_bug.cgi?id=1496517 Yes, should include that fix too, being the fixing libvirt package already in CentOS 7.5. Awesome thanks! qemu-kvm-ev with latest CVE fixes finally landed on mirror.centos.org. Build is in progress: https://jenkins.ovirt.org/job/ovirt-node-ng_ovirt-4.2_build-artifacts-el7-x86_64/282/ (In reply to Sandro Bonazzola from comment #6) > qemu-kvm-ev with latest CVE fixes finally landed on mirror.centos.org. > Build is in progress: > https://jenkins.ovirt.org/job/ovirt-node-ng_ovirt-4.2_build-artifacts-el7- > x86_64/282/ Correction, the job is https://jenkins.ovirt.org/job/ovirt-node-ng_ovirt-4.2_build-artifacts-el7-x86_64/283/ RPM for updating existing installations pushed to release server, pending an ISO ISO building here: https://jenkins.ovirt.org/job/ovirt-node-ng_ovirt-4.2_build-artifacts-el7-x86_64/284/ Test version: ovirt-node-ng-installer-ovirt-4.2-2018052421.iso imgbased-1.0.15-1.el7.centos.noarch kernel-3.10.0-862.3.2.el7.x86_64 libvirt-client-3.9.0-14.el7_5.5.x86_64 libvirt-daemon-3.9.0-14.el7_5.5.x86_64 qemu-kvm-ev-2.10.0-21.el7_5.3.1.x86_64 Test result: oVirt Node 4.2.3 include correct kernel and libvirt CVE version. @Sandor, For qemu-kvm-ev package, is this expect CVE fix version? # rpm -qa| grep qemu-kvm qemu-kvm-ev-2.10.0-21.el7_5.3.1.x86_64 qemu-kvm-common-ev-2.10.0-21.el7_5.3.1.x86_64 Thanks. (In reply to cshao from comment #9) > @Sandor, > For qemu-kvm-ev package, is this expect CVE fix version? > > # rpm -qa| grep qemu-kvm > qemu-kvm-ev-2.10.0-21.el7_5.3.1.x86_64 > qemu-kvm-common-ev-2.10.0-21.el7_5.3.1.x86_64 Yes, here's the changelog: * Mon May 21 2018 Sandro Bonazzola <sbonazzo> - ev-2.10.0-21.el7_5.3.1 - Removing RH branding from package name * Fri May 11 2018 Miroslav Rezanina <mrezanin> - 2.10.0-21.el7_5.3 - kvm-i386-define-the-ssbd-CPUID-feature-bit-CVE-2018-3639.patch [bz#1574214] - Resolves: bz#1574214 (EMBARGOED CVE-2018-3639 qemu-kvm: Kernel: omega-4 [rhel-7.5.z]) (In reply to Sandro Bonazzola from comment #8) > ISO building here: > https://jenkins.ovirt.org/job/ovirt-node-ng_ovirt-4.2_build-artifacts-el7- > x86_64/284/ ISO build failed due to infra issue. Rebuilding:https://jenkins.ovirt.org/job/ovirt-node-ng_ovirt-4.2_build-artifacts-el7-x86_64/285/ Builds pushed to release server, will be on mirrors shortly. (In reply to Sandro Bonazzola from comment #11) > (In reply to Sandro Bonazzola from comment #8) > > ISO building here: > > https://jenkins.ovirt.org/job/ovirt-node-ng_ovirt-4.2_build-artifacts-el7- > > x86_64/284/ > > ISO build failed due to infra issue. > Rebuilding:https://jenkins.ovirt.org/job/ovirt-node-ng_ovirt-4.2_build- > artifacts-el7-x86_64/285/ Test version: ovirt-node-ng-installer-ovirt-4.2-2018052506.iso imgbased-1.0.15-1.el7.centos.noarch kernel-3.10.0-862.3.2.el7.x86_64 libvirt-client-3.9.0-14.el7_5.5.x86_64 libvirt-daemon-3.9.0-14.el7_5.5.x86_64 qemu-kvm-ev-2.10.0-21.el7_5.3.1.x86_64 Test result: oVirt Node 4.2.3 include correct kernel & qemu-kvm-ev and libvirt CVE version. |