Bug 1651761 - Rebase audit package to 2.8.5 to pick up bug fixes
Summary: Rebase audit package to 2.8.5 to pick up bug fixes
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: audit
Version: 7.6
Hardware: All
OS: Linux
medium
medium
Target Milestone: rc
: ---
Assignee: Steve Grubb
QA Contact: Ondrej Moriš
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-11-20 17:40 UTC by Steve Grubb
Modified: 2019-08-06 13:03 UTC (History)
3 users (show)

Fixed In Version: audit-2.8.5-2.el7
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-08-06 13:03:45 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2019:2191 None None None 2019-08-06 13:03:53 UTC

Description Steve Grubb 2018-11-20 17:40:07 UTC
Description of problem:
There are a number of bugs that have been found and fixed on the maintenance branch of audit-2.8 that should be picked up to avoid problems. These include:

- Mark netlabel events as simple events so that get processed quicker
- When audispd is reconfiguring, only SIGHUP plugins with valid pid (#1614833)
- Add 30-ospp-v42.rules to meet new Common Criteria requirements
- In aureport, fix segfault in file report
- Add auparse_normalizer support for labeled networking events
- Fix memory leak in audisp-remote plugin when using krb5 transport. (#1622194)
- Event aging is off by a second
- In ausearch/auparse, correct event ordering to process oldest first
- auparse_reset was not clearing everything it should
- In ausearch/report, lightly parse selinux portion of USER_AVC events

Comment 3 Steve Grubb 2019-03-01 21:56:49 UTC
audit-2.8.5 was released and built in Fedora.

Comment 4 Steve Grubb 2019-03-05 18:05:43 UTC
audit-2.8.5-1.el7 was built to address this issue.

Comment 6 Steve Grubb 2019-03-27 15:18:23 UTC
A memory leak in libauparse was reported upstream. Respinning to pick up this important fix.

Comment 7 Steve Grubb 2019-03-27 16:51:59 UTC
audit-2.8.5-2.el7 was created to pickup this important bug fix.

Comment 8 Ondrej Moriš 2019-06-12 11:11:59 UTC
Successfully verified.

(In reply to Steve Grubb from comment #0)
> Description of problem:
> There are a number of bugs that have been found and fixed on the maintenance
> branch of audit-2.8 that should be picked up to avoid problems. These
> include:
> 
> - When audispd is reconfiguring, only SIGHUP plugins with valid pid
> (#1614833)

Verified - https://bugzilla.redhat.com/show_bug.cgi?id=1614833#c15.

> - In aureport, fix segfault in file report

Verified - https://bugzilla.redhat.com/show_bug.cgi?id=1705376#c5

> - Fix memory leak in audisp-remote plugin when using krb5 transport.
> (#1622194)

Verified - https://bugzilla.redhat.com/show_bug.cgi?id=1622194#c8.

The following changes were tested SanityOnly (ie. complete Sanity and Regression testing):

> - Add 30-ospp-v42.rules to meet new Common Criteria requirements
> - Mark netlabel events as simple events so that get processed quicker
> - Add auparse_normalizer support for labeled networking events
> - Event aging is off by a second
> - In ausearch/auparse, correct event ordering to process oldest first
> - auparse_reset was not clearing everything it should
> - In ausearch/report, lightly parse selinux portion of USER_AVC events
> - A memory leak in libauparse

Comment 10 errata-xmlrpc 2019-08-06 13:03:45 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2019:2191


Note You need to log in before you can comment on or make changes to this bug.