Weekly Roundup 2018 – Weeks 20 & 21:

Now that we’re starting to recover from the Grand Update, the mad flow of security and bugfix updates is resuming (see below), and tmb warns of more Spectre-related updates coming:

Spectre… “the gift that keeps giving…”

https://www.phoronix.com/scan.php?page=news_item&px=Spectre-V3-V4-Vulnerabilities

Upstream kernel 4.14 branch has the fixes/mitigation backports for variant 4 currently going through stable queue review process and should be released tonight / tomorrow after which I will release it to cauldron and mga6 testing.

Spectre v3A will get microcode fixes in the coming weeks so we’ll get to that part later…

Kernel 4.14 is indeed in testing for both Cauldron and Mga6, so should appear in your update queues soon. Meanwhile, a list of the updates since the last roundup:

Security fixes:

  • perl     Mga5, 6
  • gnupg2      Mga5, 6
  • graphite2      Mga5, 6
  • librelp      Mga5, 6
  • libtiff      Mga5, 6
  • wget      Mga5, 6
  • quassel      Mga5, 6
  • libsndfile      Mga5, 6
  • pdns      Mga6
  • bctoolbox, hiawatha, mbedtls, shadowsocks-libev, dolphin-emu Mga6
  • pdns-recursor      Mga6
  • miniupnpc      Mga6
  • kernel, kernel-userspace-headers, kmod-vboxadditions, kmod-virtualbox, kmod-xtables-addons, wireguard-tools      Mga6
  • firefox, firefox-l10n, nss, rootcerts      Mga6
  • 389-ds-base      Mga6
  • libraw      Mga6
  • exempi      Mga6
  • golang      Mga6
  • util-linux      Mga6
  • spring-ldap      Mga6
  • libpam4j      Mga6

Bugfixes (all Mga6):

  • kdenlive
  • kbookmarks, kcmutils, kcompletion, kdnssd, kitemviews, kjobwidgets, knewstuff, knotifyconfig, kpty, ktextwidgets, kunitconversion, kxmlrpcclient
  • lxterminal
  • nvidia-current, ldetect-lst
  • kodi
  • java-1.8.0-openjfx
  • 0ad, 0ad-data, sodium
  • psi
  • qgis
  • qelectrotech
  • mc
  • tellico
  • darktable
  • sddm
  • twinkle
  • broadcom-wl
  • lm_sensors
  • ldetect-lst, nvidia-current
  • wesnoth
  • youtube-dl
  • ntp
  • mesa, libdrm
  • kbookmarks, kcmutils, kcompletion, kdnssd, kitemviews, kjobwidgets, knewstuff, knotifyconfig, kpty, ktextwidgets, kunitconversion, kxmlrpcclient

…and around 650 updates went into Cauldron.

You can catch up with progress any time at the usual places: Mageia Advisories, the Mageia AppDBPkgSubmit to see the last 48 hours, and Bugzilla to see what’s currently happening.

This entry was posted in Weekly roundup. Bookmark the permalink.

Curious about Mageia? Download it, give it a try and tell us how you feel about it.

Want to bring something to it? Learn how you can contribute and donate.