Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-151408

AVC denial for keylime_verifier

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • rhel-10.2
    • keylime
    • None
    • None
    • None
    • rhel-security-special-projects
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • All
    • None

      What were you trying to do that didn't work?

       

      With the updated keylime package this AVC appears:

      ---- time->Mon Feb 23 12:14:48 2026 type=PROCTITLE msg=audit(1771848888.180:855): proctitle=2F7573722F62696E2F707974686F6E33002F7573722F62696E2F6B65796C696D655F7665726966696572 type=SYSCALL msg=audit(1771848888.180:855): arch=c0000015 syscall=33 success=no exit=-13 a0=7fffac4bc858 a1=0 a2=78 a3=0 items=0 ppid=1 pid=15531 auid=4294967295 uid=989 gid=989 euid=989 suid=989 fsuid=989 egid=989 sgid=989 fsgid=989 tty=(none) ses=4294967295 comm="keylime_verifie" exe="/usr/bin/python3.12" subj=system_u:system_r:keylime_server_t:s0 key=(null) type=AVC msg=audit(1771848888.180:855): avc: denied { read } for pid=15531 comm="keylime_verifie" name="net" dev="proc" ino=4026531845 scontext=system_u:system_r:keylime_server_t:s0 tcontext=system_u:object_r:proc_net_t:s0 tclass=lnk_file permissive=0

       

      I didn't notice any impact on a functionality.

      Please provide the package NVR for which the bug is seen:

      keylime-selinux-7.14.1-1.el10.noarch keylime-base-7.14.1-1.el10.s390x

       

      How reproducible is this bug?:

      frequent

      Steps to reproduce

      1. start the verifier, registrar
      2.  
      3.  

      Expected results

      AVC

      Actual results

      no AVC

              scorreia@redhat.com Sergio Correia
              ksrot@redhat.com Karel Srot
              Sergio Correia Sergio Correia
              Karel Srot Karel Srot
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: