Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-59223

SELinux prevents the sa-update service from doing a status check on the mimedefang service

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • rhel-security-selinux
    • ssg_security
    • None
    • QE ack
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • None
    • Hide

      The automated test does not trigger SELinux denials.

      Show
      The automated test does not trigger SELinux denials.
    • None
    • Automated
    • Unspecified Release Note Type - Unknown
    • All
    • None

      What were you trying to do that didn't work?

      What is the impact of this issue to you?

      The test scenario works as expected, but the SELinux denial appears.

      Please provide the package NVR for which the bug is seen:

      mimedefang-3.4.1-1.el9.x86_64
      selinux-policy-38.1.44-1.el9.noarch
      selinux-policy-devel-38.1.44-1.el9.noarch
      selinux-policy-targeted-38.1.44-1.el9.noarch
      spamassassin-3.4.6-6.el9.x86_64

      How reproducible is this bug?:

      always

      Steps to reproduce

      1. get a RHEL-9.5 machine (targeted policy is active)
      2. install the mimedefang package (comes from EPEL)
      3. run the following automated test: /CoreOS/selinux-policy/Regression/bz499701-spamd-dies-if-kill-HUP
      4. search for SELinux denials

      Expected results

      no SELinux denials

      Actual results

      ----
      type=USER_AVC msg=audit(09/18/2024 02:41:36.362:404) : pid=1 uid=root auid=unset ses=unset subj=system_u:system_r:init_t:s0 msg='avc:  denied  { status } for auid=unset uid=root gid=root path=/usr/lib/systemd/system/mimedefang.service cmdline="" function="mac_selinux_filter" scontext=system_u:system_r:spamd_update_t:s0 tcontext=system_u:object_r:systemd_unit_file_t:s0 tclass=service permissive=0 exe=/usr/lib/systemd/systemd sauid=root hostname=? addr=? terminal=?' 
      ----
      

              rhn-support-zpytela Zdenek Pytela
              mmalik@redhat.com Milos Malik
              Zdenek Pytela Zdenek Pytela
              Milos Malik Milos Malik
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: