VERIFIED in 5.9.2.4
I created a role/group/user that was restricted to user/group ownership and a tag. That user was able to view catalog items that were tagged only OR un-tagged but group (or user owned).
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.
https://access.redhat.com/errata/RHSA-2018:1328