Bug 2299033

Summary: SELinux is preventing chromium-browse from using the execheap access on a process.
Product: [Fedora] Fedora Reporter: Mario Smeh <mario.smeh>
Component: chromiumAssignee: Than Ngo <than>
Status: CLOSED DUPLICATE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 39CC: cpswaim, kparal, mario.smeh, spotrh, suraj.ghimire7, than, yaneti
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2024-07-31 06:24:50 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Mario Smeh 2024-07-20 17:00:40 UTC
Description of problem:
SELinux is preventing chromium-browse from using the execheap access on a process.

Plugin: allow_execheap 
 The chromium-browse application attempted to change the access protection of
memory on the heap (e.g., allocated using malloc).  This is a potential security
problem.  Applications should not be doing this. Applications are sometimes
coded incorrectly and request this permission.  The SELinux Memory Protection
Tests web page explains how to remove this requirement.  If chromium-browse does
not work and you need it to work, you can configure SELinux temporarily to allow
this access until the application is fixed. Please file a bug report against
this package.

Version-Release number of selected component (if applicable):
chromium-common-0:126.0.6478.182-1.fc39.x86_64                                                                                                                                                           chromium-0:126.0.6478.182-1.fc39.x86_64 


How reproducible:


Steps to Reproduce:
1.Start chromium browser
2.
3.

Actual results:
SELinux alert

Expected results:
without SELinux alert

Additional info:

Comment 1 Kamil Páral (Red Hat) 2024-07-31 06:24:50 UTC

*** This bug has been marked as a duplicate of bug 2254434 ***