[SRU] VirtualBox needs Security Patches

Bug #1746316 reported by Lonnie Lee Best
24
This bug affects 2 people
Affects Status Importance Assigned to Milestone
kbuild (Ubuntu)
Fix Released
Undecided
Unassigned
Xenial
Fix Released
Undecided
Unassigned
Artful
Fix Released
Undecided
Unassigned
virtualbox (Ubuntu)
Fix Released
Undecided
Gianfranco Costamagna
Xenial
Fix Released
Undecided
Gianfranco Costamagna
Artful
Fix Released
Undecided
Gianfranco Costamagna
virtualbox-ext-pack (Ubuntu)
Fix Released
Undecided
Unassigned
Xenial
Fix Released
Undecided
Unassigned
Artful
Fix Released
Undecided
Unassigned
virtualbox-guest-additions-iso (Ubuntu)
Fix Released
Undecided
Unassigned
Xenial
Fix Released
Undecided
Unassigned
Artful
Fix Released
Undecided
Unassigned

Bug Description

VirtualBox in 16.04 LTS needs an upgraded software version to receive needed security patches:
https://www.techrepublic.com/article/10-new-vm-escape-vulnerabilities-discovered-in-virtualbox/

Doing this will probably also fix this bug:
https://bugs.launchpad.net/ubuntu/+source/virtualbox/+bug/1736116

ProblemType: Bug
DistroRelease: Ubuntu 16.04
Package: virtualbox (not installed)
ProcVersionSignature: Ubuntu 4.13.0-32.35~16.04.1-generic 4.13.13
Uname: Linux 4.13.0-32-generic x86_64
ApportVersion: 2.20.1-0ubuntu2.15
Architecture: amd64
CurrentDesktop: Unity
Date: Tue Jan 30 13:01:27 2018
InstallationDate: Installed on 2017-10-20 (102 days ago)
InstallationMedia: Ubuntu 16.04.3 LTS "Xenial Xerus" - Release amd64 (20170801)
SourcePackage: virtualbox
UpgradeStatus: No upgrade log present (probably fresh install)

CVE References

Revision history for this message
Lonnie Lee Best (launchpad-startport) wrote :
summary: - upgrade-software-version - Security Patch
+ VirtualBox needs Security Patches
Revision history for this message
Gianfranco Costamagna (costamagnagianfranco) wrote : Re: VirtualBox needs Security Patches
Changed in virtualbox (Ubuntu):
status: New → In Progress
Revision history for this message
Gianfranco Costamagna (costamagnagianfranco) wrote :

I uploaded them in unapproved queue

Changed in virtualbox (Ubuntu):
assignee: nobody → LocutusOfBorg (costamagnagianfranco)
summary: - VirtualBox needs Security Patches
+ [SRU] VirtualBox needs Security Patches
Changed in virtualbox (Ubuntu Xenial):
status: New → In Progress
Changed in virtualbox (Ubuntu Artful):
status: New → In Progress
Revision history for this message
Gianfranco Costamagna (costamagnagianfranco) wrote :

Please look at bug: 1736116 for an SRU template

Changed in virtualbox (Ubuntu Xenial):
assignee: nobody → LocutusOfBorg (costamagnagianfranco)
Changed in virtualbox (Ubuntu Artful):
assignee: nobody → LocutusOfBorg (costamagnagianfranco)
Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Sadly this is not something I am willing to accept in this state as an SRU with my SRU reviewer hat on. The bug is missing the standard SRU template information, with a detailed test case to be performed and the regression potential analysis. Sure, we all know that the recent security patches should be present in every stable series, but this does not warrant us skipping the usual SRU policy. Both uploads generally are new major upstream releases, composed of a huge diff (13 MB for xenial). Letting this in without a plan of testing that would make sure users are not broken with a jump like this is not acceptable.

There does not seem to be a long-standing MRE for virtualbox, so we're also missing all the essential information that would allow us to accept an upload like this. Does virtualbox provide a sufficient test coverage for all the changes introduced? How is the autopkgtest coverage for the package? Please refer to the microreleases section of the policy for all the info we'd need to have in easily consumable format [1].

In other cases this bug might require an ACK from a technical board member as well.

That being said, for now I cannot accept it until all the criteria are fulfilled.

[1] https://wiki.ubuntu.com/StableReleaseUpdates#New_upstream_microreleases

Revision history for this message
Łukasz Zemczak (sil2100) wrote :

The bare minimum, I suppose, would be to provide us with some general set of test steps testers should perform to check if anything that's not already broken regressed or not. The related bug with 4.13 kernels seems to impact xenial with the HWE stack - but since the regular 4.4 kernels still work, I guess we'd need to define a set of general tests that should be performed after the package lands in -proposed to get an overall feel of whether things seem to work as expected.

Could you provide such a test case? I guess that would make the SRU minimal-compliant enough for me to accept it.

Thanks!

Revision history for this message
Gianfranco Costamagna (costamagnagianfranco) wrote :
Download full text (3.3 KiB)

Hello, the MRE has been discussed many times, e.g. I did the same work a lot of times, including describing the MRE exception paperwork.

e.g. LP: #1594493
LP: #1629870 (here you can see why the upstream testsuite is better than autopkgtests)
LP: #1674819
LP: #1683965
LP: #1729568

If we compare the debdiff I got uploaded for trusty, the debdiff is even worse

diff from 4.3.10-dfsg-1 (in Debian) to 4.3.34-dfsg-1+deb8u1ubuntu1.14.04.1 (13.0 MiB)

Also xenial has been bumped from 5.0.18 to 5.0.40, just in 4 minor updates, but the debdiff between what is in release, and what is in updates is scary too.

Just to be clear on all the above scary debdiffs, the TOTAL number of bugs opened because of them is...

ONE :)
(I named the virtualbox and virtualbox-hwe file init files with the same alias, so installing them without purging the other one resulted in a init system warning).
I fixed that one in a minor update, as soon as I found out the root cause for it.

If we consider the upstream debdiff, ZERO new bugs found.

That said, I understand the rationale for having a reproducing testcase, while security fixes don't need it usually, I can say that the case for testing is:

- install a xenial/artful guest machine.
  - check if 3d works, both enabled and disabled.
  - check if other guest machines still work, e.g. Windows/Other linuxes
  - check if 3d with HWE stack still work, reboot and see if everything works as expected.
  - run xenial with old and new hwe kernels, it should boot in both cases

  ^^ do the same with virtualbox-guest-additions-iso package, after removing the guest* apt stuff

This way you can test the guest stuff

- install virtualbox inside that xenial/artful guest machine, and install another linux inside that VM.
  - everything should run as expected, except for being slow (a VM inside a VM needs a lot of powerful hardware)

This is the testsuite I usually run, before asking for an SRU/MRE accept.

I also ask a lot of colleagues to test my ppa, and their machines, so I can say I'm happy with the upload, even before filing the paperwork.

That said, upstream has a really serious (not public) testsuite, they run it with the packages their provide, and this is the best reason for sticking with upstream new releases, instead of just cherry-picking new patches, because I don't want to diverge from their code, this makes regressions easier to track/reproduce, and fixes to be applied.

I never got a regression, even if in all the cases I was scared about the debdiffs, and I really think even with this upload we will be safe to go.

I case the package goes in proposed, I'll test artful in my laptop (I still run artful here :p )
and xenial with the VM I usually use.

I'll report back all the new testing done, if you care, but honestly the tests we will need, will come as new bug reports in a matter of *minutes* after the upload goes in proposed
(virtualbox is a really strange package, each time I mess up with something, it really takes minutes to get the first bug report in Debian or Ubuntu).
I can't test different hardware/CPU vendors (specially because of such CVEs), but I think monitoring new bug reports is the best way we can test i...

Read more...

Revision history for this message
Gianfranco Costamagna (costamagnagianfranco) wrote :

BTW, bugs like LP: #1754991 can be probably also considered duplicated of this one, so confirming their fix will be sufficient to confirm also this one (the Spectre/Meltdown kernel fixes needs to be followed by virtualbox changes too)

Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Ok, this is now more clear to me from the SRU-team's POV, thanks. During verification please briefly describe some of the test-cases you have performed and I'll be on cloud nine.

Changed in virtualbox (Ubuntu Artful):
status: In Progress → Fix Committed
tags: added: verification-needed verification-needed-artful
Revision history for this message
Łukasz Zemczak (sil2100) wrote : Please test proposed package

Hello Lonnie, or anyone else affected,

Accepted virtualbox into artful-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/virtualbox/5.1.34-dfsg-0ubuntu1.17.10.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-artful to verification-done-artful. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-artful. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

Changed in virtualbox-guest-additions-iso (Ubuntu Artful):
status: New → Fix Committed
Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Hello Lonnie, or anyone else affected,

Accepted virtualbox-guest-additions-iso into artful-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/virtualbox-guest-additions-iso/5.1.34-0ubuntu1.17.10.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-artful to verification-done-artful. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-artful. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

Revision history for this message
Łukasz Zemczak (sil2100) wrote :

I am for now not accepting the virtualbox-ext-pack for artful as I first would like to get confirmation about something: looking at the debian/control and debian/rules version variables, those seem to be using the 5.1.32 version string while the package itself is versioned as 5.1.34. Is that a mistake? Or is that intentional?

Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Hello Lonnie, or anyone else affected,

Accepted virtualbox into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/virtualbox/5.1.34-dfsg-0ubuntu1.16.04.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-xenial to verification-done-xenial. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-xenial. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

Changed in virtualbox (Ubuntu Xenial):
status: In Progress → Fix Committed
tags: added: verification-needed-xenial
Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Hello Lonnie, or anyone else affected,

Accepted virtualbox-hwe into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/virtualbox-hwe/5.1.34-dfsg-0ubuntu1.16.04.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-xenial to verification-done-xenial. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-xenial. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

Revision history for this message
Gianfranco Costamagna (costamagnagianfranco) wrote :

@sil2100 thanks!

>I am for now not accepting the virtualbox-ext-pack for artful as I first would like to get confirmation about something: looking at the debian/control and debian/rules version variables, those seem to be using the 5.1.32 version string while the package itself is versioned as 5.1.34. Is that a mistake? Or is that intentional?

it is an useless variable. we use DEB_VERSION_UPSTREAM and not that variable to compute runtime dependencies.

that variable is used only to create a new fake tarball, just to import-orig --pristine-tar it
VERSION=5.1.32
tarball:
        mkdir virtualbox-ext-pack_$(VERSION)
        tar cJvf virtualbox-ext-pack_$(VERSION).orig.tar.xz virtualbox-ext-pack_$(VERSION)
        rm -rf virtualbox-ext-pack_$(VERSION)
        mv virtualbox-ext-pack_$(VERSION).orig.tar.xz ..

so, I can bump it, or you can accept the current one, the resulting deb will be just the same!
let me know if you want to reject and I'll quickly reupload

Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Hello Lonnie, or anyone else affected,

Accepted kbuild into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/kbuild/1:0.1.9998svn2814+dfsg-2~ubuntu16.04.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-xenial to verification-done-xenial. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-xenial. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

Changed in kbuild (Ubuntu Artful):
status: New → Fix Released
Changed in kbuild (Ubuntu Xenial):
status: New → Fix Committed
Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Hello Lonnie, or anyone else affected,

Accepted virtualbox-guest-additions-iso into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/virtualbox-guest-additions-iso/5.1.34-0ubuntu1.16.04.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-xenial to verification-done-xenial. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-xenial. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

Changed in virtualbox-guest-additions-iso (Ubuntu Xenial):
status: New → Fix Committed
Changed in virtualbox-ext-pack (Ubuntu Artful):
status: New → Fix Committed
Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Hello Lonnie, or anyone else affected,

Accepted virtualbox-ext-pack into artful-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/virtualbox-ext-pack/5.1.34-0ubuntu1.17.10.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-artful to verification-done-artful. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-artful. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

Changed in virtualbox-ext-pack (Ubuntu Xenial):
status: New → Fix Committed
Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Hello Lonnie, or anyone else affected,

Accepted virtualbox-ext-pack into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/virtualbox-ext-pack/5.1.34-0ubuntu1.16.04.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-xenial to verification-done-xenial. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-xenial. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Hello Lonnie, or anyone else affected,

Accepted virtualbox into artful-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/virtualbox/5.1.34-dfsg-0ubuntu1.17.10.2 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-artful to verification-done-artful. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-artful. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Hello Lonnie, or anyone else affected,

Accepted virtualbox-guest-additions-iso into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/virtualbox-guest-additions-iso/5.1.34-0ubuntu1.16.04.2 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-xenial to verification-done-xenial. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-xenial. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Hello Lonnie, or anyone else affected,

Accepted virtualbox into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/virtualbox/5.1.34-dfsg-0ubuntu1.16.04.2 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-xenial to verification-done-xenial. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-xenial. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Hello Lonnie, or anyone else affected,

Accepted virtualbox-hwe into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/virtualbox-hwe/5.1.34-dfsg-0ubuntu1.16.04.2 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-xenial to verification-done-xenial. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-xenial. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

Revision history for this message
Gianfranco Costamagna (costamagnagianfranco) wrote :

Test results will be reported on #1736116

tags: added: verification-done verification-done-artful verification-done-xenial
removed: verification-needed verification-needed-artful verification-needed-xenial
Revision history for this message
Donk (donk) wrote :

Hello,
The package virtualbox-ext-pack (5.1.34-0ubuntu1.16.04.1) from xenial-proposed install the version 5.1.32 of the VirtualBox Extension Pack, instead of the 5.1.34.

term.log:

Paramétrage de virtualbox-ext-pack (5.1.34-0ubuntu1.16.04.1) ...
virtualbox-ext-pack: downloading: http://download.virtualbox.org/virtualbox/5.1.32/Oracle_VM_VirtualBox_Extension_Pack-5.1.32.vbox-extpack
The file will be downloaded into /usr/share/virtualbox-ext-pack
License accepted.
0%...10%...20%...30%...40%...50%...60%...70%...80%...90%...100%
Successfully installed "Oracle VM VirtualBox Extension Pack".

Revision history for this message
Gianfranco Costamagna (costamagnagianfranco) wrote :

oops, fixed and reuploaded

Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Hello Lonnie, or anyone else affected,

Accepted virtualbox-ext-pack into artful-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/virtualbox-ext-pack/5.1.34-0ubuntu1.17.10.2 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-artful to verification-done-artful. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-artful. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

tags: added: verification-needed verification-needed-artful
removed: verification-done verification-done-artful
tags: added: verification-needed-xenial
removed: verification-done-xenial
Revision history for this message
Łukasz Zemczak (sil2100) wrote :

Hello Lonnie, or anyone else affected,

Accepted virtualbox-ext-pack into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/virtualbox-ext-pack/5.1.34-0ubuntu1.16.04.2 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed.Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested and change the tag from verification-needed-xenial to verification-done-xenial. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed-xenial. In either case, without details of your testing we will not be able to proceed.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

tags: added: verification-done verification-done-artful verification-done-xenial
removed: verification-needed verification-needed-artful verification-needed-xenial
Revision history for this message
Hans Joachim Desserud (hjd) wrote :

I've installed virtualbox (and virtualbox-qt) 5.1.34-dfsg-0ubuntu1.17.10.2 from artful-proposed. I can confirm that it fixes bug 1754991. I haven't done a thorough regression test, but everything else seems to work as expected.

Thanks for updating, LocutusOfBorg :)

Changed in virtualbox-ext-pack (Ubuntu):
status: New → Fix Released
Changed in kbuild (Ubuntu):
status: New → Fix Released
Changed in virtualbox (Ubuntu):
status: In Progress → Fix Released
Changed in virtualbox-guest-additions-iso (Ubuntu):
status: New → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package kbuild - 1:0.1.9998svn2814+dfsg-2~ubuntu16.04.1

---------------
kbuild (1:0.1.9998svn2814+dfsg-2~ubuntu16.04.1) xenial; urgency=medium

  * SRU to xenial, to make virtualbox 5.1 build correctly
  * New upstream version 5.1.32-dfsg
    LP: #1746316 -> security patches for spectre and meltdown
    LP: #1736116 -> freeze with kernel >= 4.13

 -- Gianfranco Costamagna <email address hidden> Fri, 02 Feb 2018 14:51:36 +0100

Changed in kbuild (Ubuntu Xenial):
status: Fix Committed → Fix Released
Revision history for this message
Chris Halse Rogers (raof) wrote : Update Released

The verification of the Stable Release Update for kbuild has completed successfully and the package has now been released to -updates. Subsequently, the Ubuntu Stable Release Updates Team is being unsubscribed and will not receive messages about this bug report. In the event that you encounter a regression using the package from -updates please report a new bug using ubuntu-bug and tag the bug report regression-update so we can easily find any regressions.

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package virtualbox - 5.1.34-dfsg-0ubuntu1.17.10.2

---------------
virtualbox (5.1.34-dfsg-0ubuntu1.17.10.2) artful; urgency=medium

  * New upstream version 5.1.34-dfsg
    LP: #1746316 -> security patches for spectre and meltdown
    LP: #1736116 -> freeze with kernel >= 4.13
  * Apply 69989 to fix GL issue.
  * Lower compat level to 9

 -- Gianfranco Costamagna <email address hidden> Fri, 02 Feb 2018 13:27:46 +0100

Changed in virtualbox (Ubuntu Artful):
status: Fix Committed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package virtualbox-ext-pack - 5.1.34-0ubuntu1.17.10.2

---------------
virtualbox-ext-pack (5.1.34-0ubuntu1.17.10.2) artful; urgency=medium

  * Really point to 5.1.34 source to download

virtualbox-ext-pack (5.1.34-0ubuntu1.17.10.1) artful; urgency=medium

  * New upstream release
    LP: #1746316 -> security patches for spectre and meltdown
    LP: #1736116 -> freeze with kernel >= 4.13
  * Lower compat level to 9
  * Update license key and text.

 -- Gianfranco Costamagna <email address hidden> Thu, 15 Mar 2018 12:26:08 +0100

Changed in virtualbox-ext-pack (Ubuntu Artful):
status: Fix Committed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package virtualbox-guest-additions-iso - 5.1.34-0ubuntu1.17.10.1

---------------
virtualbox-guest-additions-iso (5.1.34-0ubuntu1.17.10.1) artful; urgency=medium

  * New upstream version 5.1.34
    LP: #1746316 -> security patches for spectre and meltdown
    LP: #1736116 -> freeze with kernel >= 4.13
  * Lower compat level to 9

 -- Gianfranco Costamagna <email address hidden> Fri, 02 Feb 2018 14:49:24 +0100

Changed in virtualbox-guest-additions-iso (Ubuntu Artful):
status: Fix Committed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package virtualbox - 5.1.34-dfsg-0ubuntu1.16.04.2

---------------
virtualbox (5.1.34-dfsg-0ubuntu1.16.04.2) xenial; urgency=medium

  * New upstream version 5.1.34-dfsg
    LP: #1746316 -> security patches for spectre and meltdown
    LP: #1736116 -> freeze with kernel >= 4.13
  * Apply 69989 to fix GL issue.
  * Lower compat level to 9

 -- Gianfranco Costamagna <email address hidden> Fri, 02 Feb 2018 13:27:46 +0100

Changed in virtualbox (Ubuntu Xenial):
status: Fix Committed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package virtualbox-ext-pack - 5.1.34-0ubuntu1.16.04.2

---------------
virtualbox-ext-pack (5.1.34-0ubuntu1.16.04.2) xenial; urgency=medium

  * Really point to 5.1.34 source to download

virtualbox-ext-pack (5.1.34-0ubuntu1.16.04.1) xenial; urgency=medium

  * New upstream release
    LP: #1746316 -> security patches for spectre and meltdown
    LP: #1736116 -> freeze with kernel >= 4.13
  * Lower compat level to 9
  * Update license key and text.

 -- Gianfranco Costamagna <email address hidden> Thu, 15 Mar 2018 12:26:08 +0100

Changed in virtualbox-ext-pack (Ubuntu Xenial):
status: Fix Committed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package virtualbox-guest-additions-iso - 5.1.34-0ubuntu1.16.04.2

---------------
virtualbox-guest-additions-iso (5.1.34-0ubuntu1.16.04.2) xenial; urgency=medium

  * New upstream version 5.1.34
    LP: #1746316 -> security patches for spectre and meltdown
    LP: #1736116 -> freeze with kernel >= 4.13
  * Lower compat level to 9

 -- Gianfranco Costamagna <email address hidden> Fri, 02 Feb 2018 14:49:24 +0100

Changed in virtualbox-guest-additions-iso (Ubuntu Xenial):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.