Bug 2151240 - SELinux is preventing ModemManager from using the 'execmem' accesses on a process.
Summary: SELinux is preventing ModemManager from using the 'execmem' accesses on a pro...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 37
Hardware: x86_64
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: abrt_hash:cc05a8e954c212f834ad04b3e80...
: 2179623 2179625 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-12-06 13:11 UTC by Simon
Modified: 2023-08-19 12:08 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2023-01-20 14:46:50 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Simon 2022-12-06 13:11:12 UTC
Description of problem:
Distro upgrade from 36 to 37, than sudo fixfiles -B onboot and Reboot
SELinux is preventing ModemManager from using the 'execmem' accesses on a process.

*****  Plugin allow_execmem (91.4 confidence) suggests   *********************

If this issue occurred during normal system operation.
Then this alert could be a serious issue and your system could be compromised.
Do
contact your security administrator and report this issue

*****  Plugin catchall (9.59 confidence) suggests   **************************

Wenn Sie denken, dass es ModemManager standardmäßig erlaubt sein sollte, execmem Zugriff auf modemmanager_t Prozesse zu erhalten.
Then sie sollten dies als Fehler melden.
Um diesen Zugriff zu erlauben, können Sie ein lokales Richtlinien-Modul erstellen.
Do
zugriff jetzt erlauben, indem Sie die nachfolgenden Befehle ausführen:
# ausearch -c 'ModemManager' --raw | audit2allow -M my-ModemManager
# semodule -X 300 -i my-ModemManager.pp

Additional Information:
Source Context                system_u:system_r:modemmanager_t:s0
Target Context                system_u:system_r:modemmanager_t:s0
Target Objects                Unbekannt [ process ]
Source                        ModemManager
Source Path                   ModemManager
Port                          <Unbekannt>
Host                          (removed)
Source RPM Packages           
Target RPM Packages           
SELinux Policy RPM            selinux-policy-targeted-37.15-1.fc37.noarch
Local Policy RPM              selinux-policy-targeted-37.15-1.fc37.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     (removed)
Platform                      Linux (removed) 6.0.11-300.fc37.x86_64 #1 SMP
                              PREEMPT_DYNAMIC Fri Dec 2 20:47:45 UTC 2022 x86_64
                              x86_64
Alert Count                   79
First Seen                    2022-12-06 13:05:21 CET
Last Seen                     2022-12-06 14:08:34 CET
Local ID                      00d93079-5481-48a6-b795-cf9513916af2

Raw Audit Messages
type=AVC msg=audit(1670332114.429:1441): avc:  denied  { execmem } for  pid=9632 comm="ModemManager" scontext=system_u:system_r:modemmanager_t:s0 tcontext=system_u:system_r:modemmanager_t:s0 tclass=process permissive=0


Hash: ModemManager,modemmanager_t,modemmanager_t,process,execmem

Version-Release number of selected component:
selinux-policy-targeted-37.15-1.fc37.noarch

Additional info:
component:      selinux-policy
reporter:       libreport-2.17.4
hashmarkername: setroubleshoot
kernel:         6.0.11-300.fc37.x86_64
type:           libreport

Comment 1 Loïc 2022-12-07 15:55:17 UTC
Similar problem has been detected:

After upgrading from Fedora 26 to 37, SELinux alerts appear after login without doing anything.
SELinux forbids execmem access to ModemManager.

hashmarkername: setroubleshoot
kernel:         6.0.11-300.fc37.x86_64
package:        selinux-policy-targeted-37.15-1.fc37.noarch
reason:         SELinux is preventing ModemManager from using the 'execmem' accesses on a process.
type:           libreport

Comment 2 Malte 2023-01-08 11:35:56 UTC
Similar problem has been detected:

After booting the system, lots of SELinux alerts will pop up within seconds.
Shutting down ModemManager will stop this.

Fedora 37 running on Thinkpad X270 with the following WWAN card:
Bus 001 Device 007: ID 2cb7:0002 Fibocom L831-EAU-00

hashmarkername: setroubleshoot
kernel:         6.0.16-300.fc37.x86_64
package:        selinux-policy-targeted-37.17-1.fc37.noarch
reason:         SELinux is preventing ModemManager from using the 'execmem' accesses on a process.
type:           libreport

Comment 3 Malte 2023-01-08 12:15:31 UTC
I've found this post on reddit claiming that ModemManager 1.18.12 will fix the issues:
https://www.reddit.com/r/Fedora/comments/z00aqc/modemmanager_repeatedly_crashing/

So i rebuild the package from the SPEC file using ModemManager 1.18.12 and libqmi 1.30.8 as a dependency. After upgrading to the new built packages and a clean reboot, the error is gone. Also "Mobile Broadband" shows up in NetworkManager again. Did not do any further tests as there is no SIM card in my laptop.

Comment 4 David Auer (2nd Account) 2023-01-09 15:38:24 UTC
Similar problem has been detected:

Upgrade to Fedora 37, on first boot and user login.

hashmarkername: setroubleshoot
kernel:         6.0.17-300.fc37.x86_64
package:        selinux-policy-targeted-37.17-1.fc37.noarch
reason:         SELinux is preventing ModemManager from using the 'execmem' accesses on a process.
type:           libreport

Comment 5 Zdenek Pytela 2023-01-19 12:32:37 UTC
Simon,

Is this issue still in place with ModemManager-1.18.12-1.fc37.x86_64?

Comment 6 Malte 2023-01-20 12:59:34 UTC
I can confirm that there are no SELinux issues anymore after upgrading to ModemManager-1.18.12-1.fc37.x86_64.

Comment 7 Zdenek Pytela 2023-01-20 14:46:50 UTC
Thank you, closing then.
Additional problems will be resolved with bz#2145005.

Comment 8 David Auer 2023-01-30 12:50:23 UTC
Unfortunately I still see this issue, just updated and after a reboot it gets triggered again:

$ ModemManager --version
ModemManager 1.18.12-1.fc37


SELinux is preventing ModemManager from using the execmem access on a process.

*****  Plugin allow_execmem (91.4 confidence) suggests   *********************

If this issue occurred during normal system operation.
Then this alert could be a serious issue and your system could be compromised.
Do
contact your security administrator and report this issue

*****  Plugin catchall (9.59 confidence) suggests   **************************

If you believe that ModemManager should be allowed execmem access on processes labeled modemmanager_t by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# ausearch -c 'ModemManager' --raw | audit2allow -M my-ModemManager
# semodule -X 300 -i my-ModemManager.pp

Additional Information:
Source Context                system_u:system_r:modemmanager_t:s0
Target Context                system_u:system_r:modemmanager_t:s0
Target Objects                Unknown [ process ]
Source                        ModemManager
Source Path                   ModemManager
Port                          <Unknown>
Host                          cdf
Source RPM Packages           
Target RPM Packages           
SELinux Policy RPM            selinux-policy-targeted-37.18-1.fc37.noarch
Local Policy RPM              selinux-policy-targeted-37.18-1.fc37.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     cdf
Platform                      Linux cdf 6.1.8-200.fc37.x86_64 #1 SMP
                              PREEMPT_DYNAMIC Tue Jan 24 20:32:16 UTC 2023
                              x86_64 x86_64
Alert Count                   15
First Seen                    2023-01-09 16:30:03 CET
Last Seen                     2023-01-30 13:42:19 CET
Local ID                      3eaf126f-7871-4eef-908e-2065a3740071

---


Do you need anything else / what can I do to help debug this?
Raw Audit Messages
type=AVC msg=audit(1675082539.211:255): avc:  denied  { execmem } for  pid=1459 comm="ModemManager" scontext=system_u:system_r:modemmanager_t:s0 tcontext=system_u:system_r:modemmanager_t:s0 tclass=process permissive=0


Hash: ModemManager,modemmanager_t,modemmanager_t,process,execmem

Comment 9 strasharo2000 2023-02-20 08:11:31 UTC
Similar problem has been detected:

Getting it on every boot. 
Thinkpad P51

hashmarkername: setroubleshoot
kernel:         6.1.11-200.fc37.x86_64
package:        selinux-policy-targeted-37.19-1.fc37.noarch
reason:         SELinux is preventing ModemManager from using the 'execmem' accesses on a process.
type:           libreport

Comment 10 Malte 2023-03-01 10:20:07 UTC
Similar problem has been detected:

Problem occurred after boot, Thinkpad X270 with Fibocom L831-EAU-00 WWAN card.

hashmarkername: setroubleshoot
kernel:         6.1.14-200.fc37.x86_64
package:        selinux-policy-targeted-37.19-1.fc37.noarch
reason:         SELinux is preventing ModemManager from using the 'execmem' accesses on a process.
type:           libreport

Comment 11 Oliver 2023-03-19 09:34:08 UTC
*** Bug 2179623 has been marked as a duplicate of this bug. ***

Comment 12 Oliver 2023-03-19 09:50:24 UTC
*** Bug 2179625 has been marked as a duplicate of this bug. ***

Comment 13 lukas.ebner 2023-04-27 11:04:13 UTC
Similar problem has been detected:

While updating the system (via dnf update) the problem occured during updating the package kmod-VirtualBox-6.2.8-100.fc36.x86_64-7.0.6-1.fc36.x86_64

hashmarkername: setroubleshoot
kernel:         6.2.9-200.fc37.x86_64
package:        selinux-policy-targeted-37.19-1.fc37.noarch
reason:         SELinux is preventing ModemManager from using the 'execmem' accesses on a process.
type:           libreport

Comment 14 Frank Büttner 2023-04-28 17:58:13 UTC
Similar problem has been detected:

Boot the system

hashmarkername: setroubleshoot
kernel:         6.2.12-200.fc37.x86_64
package:        selinux-policy-targeted-37.19-1.fc37.noarch
reason:         SELinux is preventing ModemManager from using the 'execmem' accesses on a process.
type:           libreport

Comment 15 Frank Büttner 2023-08-19 12:08:20 UTC
Similar problem has been detected:

Simple boot the system and log in.

hashmarkername: setroubleshoot
kernel:         6.4.10-100.fc37.x86_64
package:        selinux-policy-targeted-37.22-1.fc37.noarch
reason:         SELinux is preventing ModemManager from using the 'execmem' accesses on a process.
type:           libreport


Note You need to log in before you can comment on or make changes to this bug.