CONFIG_SECURITY_SELINUX_DISABLE should be disabled on KVM kernel
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
ubuntu-kernel-tests |
Fix Released
|
Undecided
|
Po-Hsu Lin | ||
linux-kvm (Ubuntu) |
Fix Released
|
Undecided
|
Po-Hsu Lin | ||
Bionic |
Fix Released
|
Medium
|
Unassigned | ||
Cosmic |
Fix Released
|
Undecided
|
Po-Hsu Lin | ||
Disco |
Fix Released
|
Undecided
|
Po-Hsu Lin |
Bug Description
The test_081_
FAIL: test_081_
Ensure CONFIG_
------
Traceback (most recent call last):
File "./test-
self.assertKer
File "./test-
self.assertKer
File "./test-
'%s option was expected to be unset in the kernel config' % name)
AssertionError: SECURITY_
ProblemType: Bug
DistroRelease: Ubuntu 18.04
Package: linux-image-
ProcVersionSign
Uname: Linux 4.15.0-1028-kvm x86_64
ApportVersion: 2.20.9-0ubuntu7.5
Architecture: amd64
Date: Thu Jan 17 04:31:59 2019
SourcePackage: linux-kvm
UpgradeStatus: No upgrade log present (probably fresh install)
Changed in linux-kvm (Ubuntu): | |
assignee: | nobody → Po-Hsu Lin (cypressyew) |
status: | New → In Progress |
Changed in ubuntu-kernel-tests: | |
status: | New → In Progress |
assignee: | nobody → Po-Hsu Lin (cypressyew) |
Changed in linux-kvm (Ubuntu Bionic): | |
importance: | Undecided → Medium |
Changed in linux-kvm (Ubuntu Bionic): | |
status: | New → Fix Committed |
Changed in linux-kvm (Ubuntu Cosmic): | |
assignee: | nobody → Po-Hsu Lin (cypressyew) |
status: | New → In Progress |
Changed in linux-kvm (Ubuntu Cosmic): | |
status: | In Progress → Fix Committed |
Changed in linux-kvm (Ubuntu Disco): | |
status: | In Progress → Fix Committed |
Changed in ubuntu-kernel-tests: | |
status: | In Progress → Fix Released |
This bug was fixed in the package linux-kvm - 4.15.0-1030.30
---------------
linux-kvm (4.15.0-1030.30) bionic; urgency=medium
* linux-kvm: 4.15.0-1030.30 -proposed tracker (LP: #1814736)
* CONFIG_ SECURITY_ SELINUX_ DISABLE should be disabled on KVM kernel SECURITY_ SELINUX_ DISABLE SECURITY_ WRITABLE_ HOOKS
(LP: #1812153)
- [Config]: disable CONFIG_
- [Config]: disable CONFIG_
[ Ubuntu: 4.15.0-46.49 ]
* linux: 4.15.0-46.49 -proposed tracker (LP: #1814726) /l1tf: Exempt zeroed PTEs from inversion linux-vxxS7y/ linux-4. 15.0/mm/ slub.c: 296! (LP: #1812086) set_conn_ values kernel_ selftests failed on KVM kernel RTLWIFI_ DEBUG_ST= n intel/ds: Fix bts_interrupt_ threshold alignment INITRAMFS_ SOURCE from defconfigs
* mprotect fails on ext4 with dax (LP: #1799237)
- x86/speculation
* kernel BUG at /build/
- iscsi target: fix session creation failure handling
- scsi: iscsi: target: Set conn->sess to NULL when iscsi_login_
fails
- scsi: iscsi: target: Fix conn_ops double free
* user_copy in user from ubuntu_
(LP: #1812198)
- selftests: user: return Kselftest Skip code for skipped tests
- selftests: kselftest: change KSFT_SKIP=4 instead of KSFT_PASS
- selftests: kselftest: Remove outdated comment
* RTL8822BE WiFi Disabled in Kernel 4.18.0-12 (LP: #1806472)
- SAUCE: staging: rtlwifi: allow RTLWIFI_DEBUG_ST to be disabled
- [Config] CONFIG_
- SAUCE: Add r8822be to signature inclusion list
* kernel oops in bcache module (LP: #1793901)
- SAUCE: bcache: never writeback a discard operation
* CVE-2018-18397
- userfaultfd: use ENOENT instead of EFAULT if the atomic copy user fails
- userfaultfd: shmem: allocate anonymous memory for MAP_PRIVATE shmem
- userfaultfd: shmem/hugetlbfs: only allow to register VM_MAYWRITE vmas
- userfaultfd: shmem: add i_size checks
- userfaultfd: shmem: UFFDIO_COPY: set the page dirty if VM_WRITE is not set
* Ignore "incomplete report" from Elan touchpanels (LP: #1813733)
- HID: i2c-hid: Ignore input report if there's no data present on Elan
touchpanels
* Vsock connect fails with ENODEV for large CID (LP: #1813934)
- vhost/vsock: fix vhost vsock cid hashing inconsistent
* SRU: Fix thinkpad 11e 3rd boot hang (LP: #1804604)
- ACPI / LPSS: Force LPSS quirks on boot
* Bionic update: upstream stable patchset 2019-01-17 (LP: #1812229)
- scsi: sd_zbc: Fix variable type and bogus comment
- KVM/Eventfd: Avoid crash when assign and deassign specific eventfd in
parallel.
- x86/apm: Don't access __preempt_count with zeroed fs
- x86/events/
- x86/MCE: Remove min interval polling limitation
- fat: fix memory allocation failure handling of match_strdup()
- ALSA: hda/realtek - Add Panasonic CF-SZ6 headset jack quirk
- ARCv2: [plat-hsdk]: Save accl reg pair by default
- ARC: Fix CONFIG_SWAP
- ARC: configs: Remove CONFIG_
- ARC: mm: allow mprotect to make stack mappings executable
- mm: memcg: fix use after free in mem_cgroup_iter()
- mm/huge_memory.c: fix data loss when splitting a file pmd
- cpufreq: intel_pstate: Register when ACPI PCCH is present
- vfio/pci: Fix potent...