Bug 1806559 - SELinux is preventing unbound from 'name_bind' accesses on the udp_socket port 61000.
Summary: SELinux is preventing unbound from 'name_bind' accesses on the udp_socket por...
Keywords:
Status: CLOSED DUPLICATE of bug 1667742
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 31
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-02-24 14:19 UTC by Ludovic Hirlimann [:Paul-muadib]
Modified: 2020-03-17 15:33 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2020-03-17 15:33:49 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ludovic Hirlimann [:Paul-muadib] 2020-02-24 14:19:37 UTC
This bug was initially created as a copy of Bug #1259766

I am copying this bug because: 

[ludovic@saraan ~]$ cat /etc/redhat-release 
Fedora release 31 (Thirty One)

I'm seeing errors like :
Feb 24 15:02:23 saraan audit[2769]: AVC avc:  denied  { name_bind } for  pid=2769 comm="unbound" src=61000 scontext=system_u:system_r:named_t:s0 tcontext=s>

in my Journal.

selinux-policy-3.14.4-48.fc31.noarch

Comment 1 Lukas Vrabec 2020-02-24 14:49:43 UTC
Hi Ludovic, 

Could you please share the whole msg? 

Please attach output of: 

# ausearch -m AVC 

Thanks,
Lukas.

Comment 2 Ludovic Hirlimann [:Paul-muadib] 2020-02-24 14:51:09 UTC
(In reply to Lukas Vrabec from comment #1)
> Hi Ludovic, 
> 
> Could you please share the whole msg? 
> 
> Please attach output of: 
> 
> # ausearch -m AVC 

time->Mon Feb 24 15:09:24 2020
type=AVC msg=audit(1582553364.360:374): avc:  denied  { name_bind } for  pid=2769 comm="unbound" src=61000 scontext=system_u:system_r:named_t:s0 tcontext=system_u:object_r:port_t:s0 tclass=udp_socket permissive=0

Comment 3 Zdenek Pytela 2020-03-17 15:33:49 UTC

*** This bug has been marked as a duplicate of bug 1667742 ***


Note You need to log in before you can comment on or make changes to this bug.