Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: Distro upgrade from 36 to 37, than sudo fixfiles -B onboot and Reboot SELinux is preventing ModemManager from using the 'execmem' accesses on a process. ***** Plugin allow_execmem (91.4 confidence) suggests ********************* If this issue occurred during normal system operation. Then this alert could be a serious issue and your system could be compromised. Do contact your security administrator and report this issue ***** Plugin catchall (9.59 confidence) suggests ************************** Wenn Sie denken, dass es ModemManager standardmäßig erlaubt sein sollte, execmem Zugriff auf modemmanager_t Prozesse zu erhalten. Then sie sollten dies als Fehler melden. Um diesen Zugriff zu erlauben, können Sie ein lokales Richtlinien-Modul erstellen. Do zugriff jetzt erlauben, indem Sie die nachfolgenden Befehle ausführen: # ausearch -c 'ModemManager' --raw | audit2allow -M my-ModemManager # semodule -X 300 -i my-ModemManager.pp Additional Information: Source Context system_u:system_r:modemmanager_t:s0 Target Context system_u:system_r:modemmanager_t:s0 Target Objects Unbekannt [ process ] Source ModemManager Source Path ModemManager Port <Unbekannt> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-37.15-1.fc37.noarch Local Policy RPM selinux-policy-targeted-37.15-1.fc37.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 6.0.11-300.fc37.x86_64 #1 SMP PREEMPT_DYNAMIC Fri Dec 2 20:47:45 UTC 2022 x86_64 x86_64 Alert Count 79 First Seen 2022-12-06 13:05:21 CET Last Seen 2022-12-06 14:08:34 CET Local ID 00d93079-5481-48a6-b795-cf9513916af2 Raw Audit Messages type=AVC msg=audit(1670332114.429:1441): avc: denied { execmem } for pid=9632 comm="ModemManager" scontext=system_u:system_r:modemmanager_t:s0 tcontext=system_u:system_r:modemmanager_t:s0 tclass=process permissive=0 Hash: ModemManager,modemmanager_t,modemmanager_t,process,execmem Version-Release number of selected component: selinux-policy-targeted-37.15-1.fc37.noarch Additional info: component: selinux-policy reporter: libreport-2.17.4 hashmarkername: setroubleshoot kernel: 6.0.11-300.fc37.x86_64 type: libreport
Similar problem has been detected: After upgrading from Fedora 26 to 37, SELinux alerts appear after login without doing anything. SELinux forbids execmem access to ModemManager. hashmarkername: setroubleshoot kernel: 6.0.11-300.fc37.x86_64 package: selinux-policy-targeted-37.15-1.fc37.noarch reason: SELinux is preventing ModemManager from using the 'execmem' accesses on a process. type: libreport
Similar problem has been detected: After booting the system, lots of SELinux alerts will pop up within seconds. Shutting down ModemManager will stop this. Fedora 37 running on Thinkpad X270 with the following WWAN card: Bus 001 Device 007: ID 2cb7:0002 Fibocom L831-EAU-00 hashmarkername: setroubleshoot kernel: 6.0.16-300.fc37.x86_64 package: selinux-policy-targeted-37.17-1.fc37.noarch reason: SELinux is preventing ModemManager from using the 'execmem' accesses on a process. type: libreport
I've found this post on reddit claiming that ModemManager 1.18.12 will fix the issues: https://www.reddit.com/r/Fedora/comments/z00aqc/modemmanager_repeatedly_crashing/ So i rebuild the package from the SPEC file using ModemManager 1.18.12 and libqmi 1.30.8 as a dependency. After upgrading to the new built packages and a clean reboot, the error is gone. Also "Mobile Broadband" shows up in NetworkManager again. Did not do any further tests as there is no SIM card in my laptop.
Similar problem has been detected: Upgrade to Fedora 37, on first boot and user login. hashmarkername: setroubleshoot kernel: 6.0.17-300.fc37.x86_64 package: selinux-policy-targeted-37.17-1.fc37.noarch reason: SELinux is preventing ModemManager from using the 'execmem' accesses on a process. type: libreport
Simon, Is this issue still in place with ModemManager-1.18.12-1.fc37.x86_64?
I can confirm that there are no SELinux issues anymore after upgrading to ModemManager-1.18.12-1.fc37.x86_64.
Thank you, closing then. Additional problems will be resolved with bz#2145005.
Unfortunately I still see this issue, just updated and after a reboot it gets triggered again: $ ModemManager --version ModemManager 1.18.12-1.fc37 SELinux is preventing ModemManager from using the execmem access on a process. ***** Plugin allow_execmem (91.4 confidence) suggests ********************* If this issue occurred during normal system operation. Then this alert could be a serious issue and your system could be compromised. Do contact your security administrator and report this issue ***** Plugin catchall (9.59 confidence) suggests ************************** If you believe that ModemManager should be allowed execmem access on processes labeled modemmanager_t by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'ModemManager' --raw | audit2allow -M my-ModemManager # semodule -X 300 -i my-ModemManager.pp Additional Information: Source Context system_u:system_r:modemmanager_t:s0 Target Context system_u:system_r:modemmanager_t:s0 Target Objects Unknown [ process ] Source ModemManager Source Path ModemManager Port <Unknown> Host cdf Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-37.18-1.fc37.noarch Local Policy RPM selinux-policy-targeted-37.18-1.fc37.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name cdf Platform Linux cdf 6.1.8-200.fc37.x86_64 #1 SMP PREEMPT_DYNAMIC Tue Jan 24 20:32:16 UTC 2023 x86_64 x86_64 Alert Count 15 First Seen 2023-01-09 16:30:03 CET Last Seen 2023-01-30 13:42:19 CET Local ID 3eaf126f-7871-4eef-908e-2065a3740071 --- Do you need anything else / what can I do to help debug this? Raw Audit Messages type=AVC msg=audit(1675082539.211:255): avc: denied { execmem } for pid=1459 comm="ModemManager" scontext=system_u:system_r:modemmanager_t:s0 tcontext=system_u:system_r:modemmanager_t:s0 tclass=process permissive=0 Hash: ModemManager,modemmanager_t,modemmanager_t,process,execmem
Similar problem has been detected: Getting it on every boot. Thinkpad P51 hashmarkername: setroubleshoot kernel: 6.1.11-200.fc37.x86_64 package: selinux-policy-targeted-37.19-1.fc37.noarch reason: SELinux is preventing ModemManager from using the 'execmem' accesses on a process. type: libreport
Similar problem has been detected: Problem occurred after boot, Thinkpad X270 with Fibocom L831-EAU-00 WWAN card. hashmarkername: setroubleshoot kernel: 6.1.14-200.fc37.x86_64 package: selinux-policy-targeted-37.19-1.fc37.noarch reason: SELinux is preventing ModemManager from using the 'execmem' accesses on a process. type: libreport
*** Bug 2179623 has been marked as a duplicate of this bug. ***
*** Bug 2179625 has been marked as a duplicate of this bug. ***
Similar problem has been detected: While updating the system (via dnf update) the problem occured during updating the package kmod-VirtualBox-6.2.8-100.fc36.x86_64-7.0.6-1.fc36.x86_64 hashmarkername: setroubleshoot kernel: 6.2.9-200.fc37.x86_64 package: selinux-policy-targeted-37.19-1.fc37.noarch reason: SELinux is preventing ModemManager from using the 'execmem' accesses on a process. type: libreport
Similar problem has been detected: Boot the system hashmarkername: setroubleshoot kernel: 6.2.12-200.fc37.x86_64 package: selinux-policy-targeted-37.19-1.fc37.noarch reason: SELinux is preventing ModemManager from using the 'execmem' accesses on a process. type: libreport
Similar problem has been detected: Simple boot the system and log in. hashmarkername: setroubleshoot kernel: 6.4.10-100.fc37.x86_64 package: selinux-policy-targeted-37.22-1.fc37.noarch reason: SELinux is preventing ModemManager from using the 'execmem' accesses on a process. type: libreport