-
Bug
-
Resolution: Done-Errata
-
Minor
-
rhel-9.5
-
selinux-policy-38.1.50-1.el9
-
None
-
Low
-
1
-
rhel-security-selinux
-
ssg_security
-
20
-
1
-
False
-
False
-
-
No
-
SELINUX 241127 - 241218
-
Approved Exception
-
Release Note Not Required
-
None
What were you trying to do that didn't work?
SELinux status: enabled
SELinuxfs mount: /sys/fs/selinux
SELinux root directory: /etc/selinux
Loaded policy name: targeted
Current mode: enforcing
Mode from config file: enforcing
Policy MLS status: enabled
Policy deny_unknown status: allowed
Memory protection checking: actual (secure)
Max kernel policy version: 33
selinux-policy-38.1.40-1.el9.noarch
time->Wed Jul 3 09:23:34 2024
type=PROCTITLE msg=audit(1719987814.638:694): proctitle="(sd-parse-elf)"
type=SYSCALL msg=audit(1719987814.638:694): arch=c000003e syscall=157 success=no exit=-1 a0=23 a1=8 a2=7f39a3340000 a3=0 items=0 ppid=72196 pid=72198 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="(sd-parse-elf)" exe="/usr/lib/systemd/systemd-coredump" subj=system_u:system_r:systemd_coredump_t:s0 key=(null)
type=AVC msg=audit(1719987814.638:694): avc: denied { sys_resource } for pid=72198 comm="(sd-parse-elf)" capability=24 scontext=system_u:system_r:systemd_coredump_t:s0 tcontext=system_u:system_r:systemd_coredump_t:s0 tclass=capability permissive=0
Please provide the package NVR for which bug is seen:
kernel-5.14.0-473.el9
selinux-policy-38.1.40-1.el9.noarch
How reproducible:
many times
Steps to reproduce
N/A
Expected results
No AVC issue
Actual results
AVC deny
beaker jobs:
https://beaker.engineering.redhat.com/jobs/9521699
https://beaker-archive.prod.engineering.redhat.com/beaker-logs/2024/07/95216/9521699/16482093/180047363/839430232/avc.log
https://beaker.engineering.redhat.com/jobs/9525306
https://beaker-archive.prod.engineering.redhat.com/beaker-logs/2024/07/95253/9525306/16487539/180090071/839701164/avc.log
- links to
-
RHBA-2024:139849 selinux-policy bug fix and enhancement update