Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-5633

avahi package has incorrect owner:group defined in payload for /var/run/avahi-daemon

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Normal Normal
    • rhel-9.5
    • rhel-9.0.0
    • avahi
    • avahi-0.8-21.el9
    • None
    • Moderate
    • rhel-plumbers
    • ssg_core_services
    • 26
    • 2
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • If docs needed, set a value
    • None
    • 57,005

      +++ This bug was initially created as a clone of Bug #2132775 +++

      Description of problem:
      When installing the avahi rpm, the provided /var/run/avahi-daemon directory has root:root ownership as seen in 'rpm -qlv | grep avahi' output. Once the service is started, ownership is changed to avahi:avahi. This causes a CAT I STIG security finding in RHEL 8 and likely will do the same with the RHEL 9 STIG once it is released.

      Version-Release number of selected component (if applicable):
      avahi-0.8-12.el9.x86_64

      How reproducible:
      Every time

      Steps to Reproduce:
      1. dnf install avahi
      2. "rpm -qlv avahi | grep 'var/run/avahi-daemon'" and note ownership
      3. systemctl start avahi-daemon
      4. "ls -ld /var/run/avahi-daemon" and note difference in ownership

      Actual results:
      Ownership in provided /var/run/avahi-daemon differ from /var/run/avahi-daemon after starting the service

      Expected results:
      Ownership in provided /var/run/avahi-daemon match the same after starting the service

      Additional info:
      The same or similar issue was previously reported in RHEL 7 but was designated 'wontfix'. Bug 1770402. I could not find this reported in RHEL 9, but hopefully I did not miss something if it has been.

              msekleta@redhat.com Michal Sekletar
              rhn-support-ngarrett Neil Garrett
              Michal Sekletar Michal Sekletar
              Daniel Rusek Daniel Rusek
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: