Bug 2217165
| Summary: | SELinux is preventing aide from using the 'execmem' accesses on a process. | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Matt Fagnani <matt.fagnani> | ||||||
| Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> | ||||||
| Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||||
| Severity: | unspecified | Docs Contact: | |||||||
| Priority: | low | ||||||||
| Version: | 38 | CC: | dwalsh, lvrabec, matt.fagnani, mmalik, nknazeko, omosnacek, pkoncity, rsroka, vmojzis, zpytela | ||||||
| Target Milestone: | --- | Keywords: | Triaged | ||||||
| Target Release: | --- | ||||||||
| Hardware: | x86_64 | ||||||||
| OS: | Unspecified | ||||||||
| Whiteboard: | abrt_hash:d4180c2b606e5f34adfd984aefb3113dd516edbe94277ba0c40247828a2b0d65;VARIANT_ID=kde; | ||||||||
| Fixed In Version: | selinux-policy-38.20-1.fc38 | Doc Type: | If docs needed, set a value | ||||||
| Doc Text: | Story Points: | --- | |||||||
| Clone Of: | Environment: | ||||||||
| Last Closed: | 2023-07-01 01:46:01 UTC | Type: | --- | ||||||
| Regression: | --- | Mount Type: | --- | ||||||
| Documentation: | --- | CRM: | |||||||
| Verified Versions: | Category: | --- | |||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||
| Embargoed: | |||||||||
| Attachments: |
|
||||||||
|
Description
Matt Fagnani
2023-06-24 16:54:04 UTC
Created attachment 1972379 [details]
File: os_info
Created attachment 1972380 [details]
File: description
Rado, Is the execmem permission request a result of the aide rebase? Did you come across it as well? I saw this execmem denial a third time within a second of aide being run from the cron job. aide completed even with the denial. aide-0.18.4-2.fc38 involved porting to pcre2 https://koji.fedoraproject.org/koji/buildinfo?buildID=2218512 https://bugzilla.redhat.com/show_bug.cgi?id=2128267 The use of pcre2 JIT-compiled regular expressions resulted in execmem denials for libvirt https://bugzilla.redhat.com/show_bug.cgi?id=2122918 proftpd https://bugzilla.redhat.com/show_bug.cgi?id=2161705 and tshark https://bugzilla.redhat.com/show_bug.cgi?id=2163800 Those cases appear to have been fixed by using dontaudit for execmem. Thank you, Matt, I am going to dontaudit it right away; still, I'd like to hear from developers if there is an issue with this approach, e.g. performance penalty. FEDORA-2023-ba070ee6ba has been submitted as an update to Fedora 38. https://bodhi.fedoraproject.org/updates/FEDORA-2023-ba070ee6ba FEDORA-2023-ba070ee6ba has been pushed to the Fedora 38 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2023-ba070ee6ba` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2023-ba070ee6ba See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates. FEDORA-2023-ba070ee6ba has been pushed to the Fedora 38 stable repository. If problem still persists, please make note of it in this bug report. |