Bug 1578909 - oVirt Node 4.2.3 respin needed including CVE fixes
Summary: oVirt Node 4.2.3 respin needed including CVE fixes
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: ovirt-node
Classification: oVirt
Component: Build
Version: 4.2
Hardware: Unspecified
OS: Unspecified
urgent
urgent
Target Milestone: ovirt-4.2.3
: 4.2
Assignee: Sandro Bonazzola
QA Contact: cshao
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-05-16 15:17 UTC by Sandro Bonazzola
Modified: 2018-05-25 12:05 UTC (History)
12 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-05-25 12:05:20 UTC
oVirt Team: Node
Embargoed:
rule-engine: ovirt-4.2+
cshao: testing_ack+


Attachments (Terms of Use)

Description Sandro Bonazzola 2018-05-16 15:17:58 UTC
oVirt Node 4.2.3 has been released before CentOS 7.5.
With CentOS 7.5 release (https://lists.centos.org/pipermail/centos-announce/2018-May/022829.html) several CVEs have been fixed, including the last disclosed one:
CESA-2018:1453 Critical CentOS 7 dhcp Security Update (https://lists.centos.org/pipermail/centos-announce/2018-May/022831.html)

We should respin oVirt Node and ship it as an async update to 4.2.3.

Comment 1 Sandro Bonazzola 2018-05-16 15:54:04 UTC
There are 45 packages being built right now including first batch update of RHEL 7.5. Worth to wait for them as well.

Comment 2 Sandro Bonazzola 2018-05-18 07:17:34 UTC
Still waiting for CentOS builds to finish.

Comment 3 Rob Sanders 2018-05-21 13:20:50 UTC
Any chance the new version will include fix for this?

https://bugzilla.redhat.com/show_bug.cgi?id=1496517

Comment 4 Sandro Bonazzola 2018-05-21 13:27:33 UTC
(In reply to Rob Sanders from comment #3)
> Any chance the new version will include fix for this?
> 
> https://bugzilla.redhat.com/show_bug.cgi?id=1496517

Yes, should include that fix too, being the fixing libvirt package already in CentOS 7.5.

Comment 5 Rob Sanders 2018-05-21 13:28:43 UTC
Awesome thanks!

Comment 6 Sandro Bonazzola 2018-05-24 15:08:28 UTC
qemu-kvm-ev with latest CVE fixes finally landed on mirror.centos.org.
Build is in progress: https://jenkins.ovirt.org/job/ovirt-node-ng_ovirt-4.2_build-artifacts-el7-x86_64/282/

Comment 7 Sandro Bonazzola 2018-05-24 20:49:54 UTC
(In reply to Sandro Bonazzola from comment #6)
> qemu-kvm-ev with latest CVE fixes finally landed on mirror.centos.org.
> Build is in progress:
> https://jenkins.ovirt.org/job/ovirt-node-ng_ovirt-4.2_build-artifacts-el7-
> x86_64/282/

Correction, the job is https://jenkins.ovirt.org/job/ovirt-node-ng_ovirt-4.2_build-artifacts-el7-x86_64/283/

RPM for updating existing installations pushed to release server, pending an ISO

Comment 8 Sandro Bonazzola 2018-05-24 20:58:09 UTC
ISO building here: https://jenkins.ovirt.org/job/ovirt-node-ng_ovirt-4.2_build-artifacts-el7-x86_64/284/

Comment 9 cshao 2018-05-25 03:17:45 UTC
Test version:
ovirt-node-ng-installer-ovirt-4.2-2018052421.iso
imgbased-1.0.15-1.el7.centos.noarch
kernel-3.10.0-862.3.2.el7.x86_64
libvirt-client-3.9.0-14.el7_5.5.x86_64
libvirt-daemon-3.9.0-14.el7_5.5.x86_64
qemu-kvm-ev-2.10.0-21.el7_5.3.1.x86_64

Test result:
oVirt Node 4.2.3 include correct kernel and libvirt CVE version.


@Sandor,
For qemu-kvm-ev package, is this expect CVE fix version?

# rpm -qa| grep qemu-kvm
qemu-kvm-ev-2.10.0-21.el7_5.3.1.x86_64
qemu-kvm-common-ev-2.10.0-21.el7_5.3.1.x86_64

Thanks.

Comment 10 Sandro Bonazzola 2018-05-25 06:32:07 UTC
(In reply to cshao from comment #9)

> @Sandor,
> For qemu-kvm-ev package, is this expect CVE fix version?
> 
> # rpm -qa| grep qemu-kvm
> qemu-kvm-ev-2.10.0-21.el7_5.3.1.x86_64
> qemu-kvm-common-ev-2.10.0-21.el7_5.3.1.x86_64

Yes, here's the changelog:
* Mon May 21 2018 Sandro Bonazzola <sbonazzo> - ev-2.10.0-21.el7_5.3.1
- Removing RH branding from package name

* Fri May 11 2018 Miroslav Rezanina <mrezanin> - 2.10.0-21.el7_5.3
- kvm-i386-define-the-ssbd-CPUID-feature-bit-CVE-2018-3639.patch [bz#1574214]
- Resolves: bz#1574214
  (EMBARGOED CVE-2018-3639 qemu-kvm: Kernel: omega-4 [rhel-7.5.z])

Comment 11 Sandro Bonazzola 2018-05-25 06:34:47 UTC
(In reply to Sandro Bonazzola from comment #8)
> ISO building here:
> https://jenkins.ovirt.org/job/ovirt-node-ng_ovirt-4.2_build-artifacts-el7-
> x86_64/284/

ISO build failed due to infra issue. Rebuilding:https://jenkins.ovirt.org/job/ovirt-node-ng_ovirt-4.2_build-artifacts-el7-x86_64/285/

Comment 12 Sandro Bonazzola 2018-05-25 08:35:33 UTC
Builds pushed to release server, will be on mirrors shortly.

Comment 13 cshao 2018-05-25 10:39:40 UTC
(In reply to Sandro Bonazzola from comment #11)
> (In reply to Sandro Bonazzola from comment #8)
> > ISO building here:
> > https://jenkins.ovirt.org/job/ovirt-node-ng_ovirt-4.2_build-artifacts-el7-
> > x86_64/284/
> 
> ISO build failed due to infra issue.
> Rebuilding:https://jenkins.ovirt.org/job/ovirt-node-ng_ovirt-4.2_build-
> artifacts-el7-x86_64/285/


Test version:
ovirt-node-ng-installer-ovirt-4.2-2018052506.iso
imgbased-1.0.15-1.el7.centos.noarch
kernel-3.10.0-862.3.2.el7.x86_64
libvirt-client-3.9.0-14.el7_5.5.x86_64
libvirt-daemon-3.9.0-14.el7_5.5.x86_64
qemu-kvm-ev-2.10.0-21.el7_5.3.1.x86_64

Test result:
oVirt Node 4.2.3 include correct kernel & qemu-kvm-ev and libvirt CVE version.


Note You need to log in before you can comment on or make changes to this bug.