Bug 785590 - SELinux is preventing /usr/bin/skype from 'mmap_zero' accesses on the None .
Summary: SELinux is preventing /usr/bin/skype from 'mmap_zero' accesses on the None .
Keywords:
Status: CLOSED CANTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 16
Hardware: x86_64
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Miroslav Grepl
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: abrt_hash:96babff465afc0379d82b0441d9...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2012-01-29 20:10 UTC by José Antonio
Modified: 2012-01-30 11:48 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2012-01-30 11:48:12 UTC
Type: ---


Attachments (Terms of Use)

Description José Antonio 2012-01-29 20:10:53 UTC
libreport version: 2.0.8
executable:     /usr/bin/python
hashmarkername: setroubleshoot
kernel:         3.2.2-1.fc16.x86_64
reason:         SELinux is preventing /usr/bin/skype from 'mmap_zero' accesses on the None .
time:           Sun 29 Jan 2012 08:10:14 PM WET

description:
:SELinux is preventing /usr/bin/skype from 'mmap_zero' accesses on the None .
:
:*****  Plugin mmap_zero (91.4 confidence) suggests  **************************
:
:If you do not think /usr/bin/skype should need to mmap low memory in the kernel.
:Then you may be under attack by a hacker, this is a very dangerous access.
:Do
:contact your security administrator and report this issue.
:
:*****  Plugin catchall (9.59 confidence) suggests  ***************************
:
:If you believe that skype should be allowed mmap_zero access on the  <Unknown> by default.
:Then you should report this as a bug.
:You can generate a local policy module to allow this access.
:Do
:allow this access for now by executing:
:# grep threaded-ml /var/log/audit/audit.log | audit2allow -M mypol
:# semodule -i mypol.pp
:
:Additional Information:
:Source Context                unconfined_u:unconfined_r:unconfined_execmem_t:s0-
:                              s0:c0.c1023
:Target Context                unconfined_u:unconfined_r:unconfined_execmem_t:s0-
:                              s0:c0.c1023
:Target Objects                 [ None ]
:Source                        threaded-ml
:Source Path                   /usr/bin/skype
:Port                          <Unknown>
:Host                          (removed)
:Source RPM Packages           
:Target RPM Packages           
:Policy RPM                    <Unknown>
:Selinux Enabled               True
:Policy Type                   targeted
:Enforcing Mode                Enforcing
:Host Name                     (removed)
:Platform                      Linux (removed) 3.2.2-1.fc16.x86_64 #1 SMP Thu
:                              Jan 26 03:21:58 UTC 2012 x86_64 x86_64
:Alert Count                   6
:First Seen                    Sun 29 Jan 2012 08:09:18 PM WET
:Last Seen                     Sun 29 Jan 2012 08:09:18 PM WET
:Local ID                      7e00dfcc-c1c9-4af2-883e-63af13f06c4b
:
:Raw Audit Messages
:type=AVC msg=audit(1327867758.800:169): avc:  denied  { mmap_zero } for  pid=9882 comm="threaded-ml" scontext=unconfined_u:unconfined_r:unconfined_execmem_t:s0-s0:c0.c1023 tcontext=unconfined_u:unconfined_r:unconfined_execmem_t:s0-s0:c0.c1023 tclass=memprotectnode=(removed) type=SYSCALL msg=audit(1327867758.800:169): arch=40000003 syscall=192 per=400000 success=no exit=4294967283 a0=0 a1=1000 a2=3 a3=22 items=0 ppid=9845 pid=9882 auid=1000 uid=1000 gid=1000 euid=1000 suid=1000 fsuid=1000 egid=1000 sgid=1000 fsgid=1000 tty=(none) ses=2 comm="threaded-ml" exe="/usr/bin/skype" subj=unconfined_u:unconfined_r:unconfined_execmem_t:s0-s0:c0.c1023 key=(null)
:
:
:Hash: threaded-ml,unconfined_execmem_t,unconfined_execmem_t,None,mmap_zero
:
:audit2allow
:
:
:audit2allow -R
:
:

Comment 1 Miroslav Grepl 2012-01-30 11:48:12 UTC
As the alert tells you, this is not something we want to allow.  You should
report it as a bug to skype. 

I would suggest you add a dontaudit rule and you would be abel to continue to use the product.


Note You need to log in before you can comment on or make changes to this bug.