Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-15398

Confined sysadm cannot execute "sudo tcpdump" command [rhel-8]

    • selinux-policy-3.14.3-133.el8
    • None
    • Moderate
    • rhel-sst-security-selinux
    • ssg_security
    • 20
    • None
    • QE ack
    • False
    • Hide

      None

      Show
      None
    • Yes
    • Red Hat Enterprise Linux
    • None
    • Hide

      System administrator that is confined by SELinux (sysadm_u) can successfully run the tcpdump command via sudo. No SELinux denials are triggered during the run.

      Show
      System administrator that is confined by SELinux (sysadm_u) can successfully run the tcpdump command via sudo. No SELinux denials are triggered during the run.
    • Pass
    • Automated
    • Bug Fix
    • Hide
      .SELinux policy contains rules for additional services and applications

      This version of the `selinux-policy` package contains additional rules. Most notably, users in the `sysadm_r` role can execute the following commands:

      * `sudo traceroute`
      * `sudo tcpdump`
      * `sudo dnf`
      Show
      .SELinux policy contains rules for additional services and applications This version of the `selinux-policy` package contains additional rules. Most notably, users in the `sysadm_r` role can execute the following commands: * `sudo traceroute` * `sudo tcpdump` * `sudo dnf`
    • Done
    • None

      What were you trying to do that didn't work?

       Users mapped to sysadm_u cannot execute `sudo tcpdump` command because `tcpdump` executes in `sysadm_sudo_t` context due to missing rule to transition.

      Please provide the package NVR for which bug is seen:

      selinux-policy

      How reproducible:

      Always

      Steps to reproduce

      1. Execute `sudo tcpdump` from a confined user mapped to `sysadm_u`

      Expected results

      Works

      Actual results

      Fails

              rhn-support-zpytela Zdenek Pytela
              rhn-support-rmetrich Renaud Métrich
              Nikola Kňažeková Nikola Kňažeková (Inactive)
              Milos Malik Milos Malik
              Jan Fiala Jan Fiala
              Votes:
              0 Vote for this issue
              Watchers:
              9 Start watching this issue

                Created:
                Updated:
                Resolved: