Bug 1411126

Summary: Suspicious detections on fresh installed system
Product: [Fedora] Fedora Reporter: redhat
Component: chkrootkitAssignee: Gwyn Ciesla <gwync>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 25CC: gwync, manuel.wolfshant
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: chkrootkit-0.52-1.fc26 chkrootkit-0.52-1.fc24 chkrootkit-0.52-1.fc25 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-04-10 16:00:57 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description redhat 2017-01-08 15:14:29 UTC
Description of problem:
chkrootkit when run on a fresh installed FC25 system reports suspicious detections.

Checking `lkm'... chkproc: nothing detected
-146    /usr/share
-1      /usr/bin
-1      /usr/sbin
-41     /lib
chkdirs: Warning: Possible LKM Trojan installed


Version-Release number of selected component (if applicable):
chkrootkit-0.50-9.fc25.x86_64

How reproducible:
Everytime you run the script chkrootkit


Steps to Reproduce:
1. # chkrootkit
2.
3.

Actual results:
Checking `lkm'... chkproc: nothing detected
-146    /usr/share
-1      /usr/bin
-1      /usr/sbin
-41     /lib
chkdirs: Warning: Possible LKM Trojan installed


Expected results:
No warning about LKM Trojan


Additional info:

Comment 1 Fedora Update System 2017-04-04 18:48:24 UTC
chkrootkit-0.52-1.fc25 has been submitted as an update to Fedora 25. https://bodhi.fedoraproject.org/updates/FEDORA-2017-8df4d86cda

Comment 2 Fedora Update System 2017-04-04 18:48:36 UTC
chkrootkit-0.52-1.fc26 has been submitted as an update to Fedora 26. https://bodhi.fedoraproject.org/updates/FEDORA-2017-b761864bd2

Comment 3 Fedora Update System 2017-04-04 18:48:45 UTC
chkrootkit-0.52-1.fc24 has been submitted as an update to Fedora 24. https://bodhi.fedoraproject.org/updates/FEDORA-2017-0e016ac083

Comment 4 Fedora Update System 2017-04-05 19:53:53 UTC
chkrootkit-0.52-1.fc24 has been pushed to the Fedora 24 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-0e016ac083

Comment 5 Fedora Update System 2017-04-05 19:54:14 UTC
chkrootkit-0.52-1.fc25 has been pushed to the Fedora 25 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-8df4d86cda

Comment 6 Fedora Update System 2017-04-05 21:54:37 UTC
chkrootkit-0.52-1.fc26 has been pushed to the Fedora 26 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-b761864bd2

Comment 7 redhat 2017-04-06 15:30:55 UTC
The update package still reports regular files as suspicious:

Searching for suspicious files and dirs, it may take a while...
/usr/lib/debug/usr/.dwz /usr/lib/modules/4.10.8-200.fc25.x86_64/.vmlinuz.hmac

# rpm -qf /usr/lib/debug/usr/.dwz
filesystem-3.2-37.fc24.x86_64
# rpm -qf /usr/lib/modules/4.10.8-200.fc25.x86_64/.vmlinuz.hmac
kernel-core-4.10.8-200.fc25.x86_64

# rpm -q chkrootkit
chkrootkit-0.52-1.fc25.x86_64

Comment 8 Fedora Update System 2017-04-10 16:00:57 UTC
chkrootkit-0.52-1.fc26 has been pushed to the Fedora 26 stable repository. If problems still persist, please make note of it in this bug report.

Comment 9 Fedora Update System 2017-04-13 22:48:12 UTC
chkrootkit-0.52-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.

Comment 10 Fedora Update System 2017-04-13 23:51:13 UTC
chkrootkit-0.52-1.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.