-
Bug
-
Resolution: Unresolved
-
Normal
-
None
-
fapolicyd-1.4.3-3.el10
-
None
-
Low
-
2
-
rhel-security-selinux
-
ssg_security
-
3
-
False
-
False
-
-
No
-
SELINUX 260107: 16, SELINUX 260218: 18
-
If docs needed, set a value
-
-
All
-
None
-
0
There is not a specific reproducer, but what we could understand is that
apparently the issue started happening after installing the packages
glibc-2.34-60.el9.i686
glibc-gconv-extra-2.34-60.el9.i686
libgcc-11.3.1-4.3.el9.i686
Inspecting source code and doing experiments did not find any possible
issue, other than incorrect type in
https://github.com/linux-application-whitelisting/fapolicyd/blob/main/src/library/file.c#L680
where it should use ELf32_Dyn and not Elf64_Dyn. The types are different,
(Elf32_Dun is 8 bytes while Elf64_Dyn is 16 bytes) but further checking the
code it should only have issues on very special 32 bit libraries, possibly
ending in a segfault.
What really should have triggered the issue was that both, fapolicyd and
sudo were updated in the same transaction.
When attempting to debug the problem, the problem just gone away with a
restart of fapolicyd.
This bug report is now as just a heads up of possible issues, probably with
rpm-plugin-fapolicyd, the condition of updating fapolicyd and sudo in the
same transaction, and probably running the update from sudo or after sudo.
- clones
-
RHEL-1357 sudo: error while loading shared libraries: libsudo_util.so.0: cannot open shared object file: No such file or directory
-
- Integration
-
- external trackers
- links to
-
RHBA-2025:155643
fapolicyd update