Bug 2021529

Summary: Secure_mode boolean allows staff SELinux user switch to unconfined
Product: Red Hat Enterprise Linux 9 Reporter: Zdenek Pytela <zpytela>
Component: selinux-policyAssignee: Zdenek Pytela <zpytela>
Status: CLOSED DUPLICATE QA Contact: Milos Malik <mmalik>
Severity: high Docs Contact: Mirek Jahoda <mjahoda>
Priority: high    
Version: 9.0CC: amkulkar, gfialova, kborole, lvrabec, mjahoda, mmalik, pkoncity, plautrba, rmetrich, ssekidde, wdh, zpytela
Target Milestone: rcKeywords: Triaged
Target Release: 9.1Flags: pm-rhel: mirror+
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Known Issue
Doc Text:
.SELinux `staff_u` users can incorrectly switch to `unconfined_r` When the `secure_mode` boolean is enabled, `staff_u` users can incorrectly switch to the `unconfined_r` role. As a consequence, `staff_u` users can perform privileged operations affecting the security of the system.
Story Points: ---
Clone Of: 1947841 Environment:
Last Closed: 2022-08-03 15:26:13 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1947841, 2022763, 2076681    
Bug Blocks: 1778780    

Comment 3 Zdenek Pytela 2021-11-16 07:35:41 UTC
*** Bug 2023462 has been marked as a duplicate of this bug. ***