Bug 2229992
Summary: | SELinux labels RIPE Atlas Probe/Anchor's /usr/sbin/ripe-atlas process as zebra_t [rhel-9.2.0.z] | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 9 | Reporter: | RHEL Program Management Team <pgm-rhel-tools> |
Component: | selinux-policy | Assignee: | Nikola Knazekova <nknazeko> |
Status: | CLOSED ERRATA | QA Contact: | Milos Malik <mmalik> |
Severity: | medium | Docs Contact: | |
Priority: | urgent | ||
Version: | 9.2 | CC: | apeetham, dbodnarc, fkrska, lvrabec, mmalik, redhat-bugzilla, zpytela |
Target Milestone: | rc | Keywords: | Triaged, ZStream |
Target Release: | --- | ||
Hardware: | x86_64 | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | selinux-policy-38.1.11-2.el9_2.4 | Doc Type: | Bug Fix |
Doc Text: |
Cause: The policy contained the /usr/sbin/rip.* regex which was too broad and matched also binaries from other components, which leads to mislabeling of ripe-atlas
Consequence: SELinux labels RIPE Atlas Probe/Anchor's /usr/sbin/ripe-atlas process as zebra_t
Fix: Label only /usr/sbin/ripd and ripngd with zebra_exec_t
Result: Other binaries are not labeled as zebra_t
|
Story Points: | --- |
Clone Of: | 2213605 | Environment: | |
Last Closed: | 2023-09-12 10:02:49 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2213605 | ||
Bug Blocks: |
Comment 10
errata-xmlrpc
2023-09-12 10:02:49 UTC
|