-
Bug
-
Resolution: Unresolved
-
Undefined
-
rhel-8.1.0
-
audit-4.0.3-1.el10
-
Yes
-
Moderate
-
Upstream
-
-
1
-
rhel-sst-security-special-projects
-
ssg_security
-
26
-
1
-
False
-
-
No
-
Red Hat Enterprise Linux
-
SECENGSP Cycle 14
-
Unspecified Release Note Type - Unknown
-
All
-
None
What were you trying to do that didn't work?
Running ausearch with the checkpoint option where the inodes for files in /var/log/auditd are greater than an unsigned 32 bit value.
What is the impact of this issue to you?
Checkpointing of audit fails and impacts my ability to send auditd events to a central SIEM.
Please provide the package NVR for which the bug is seen:
How reproducible is this bug?:
Always, once the inodes for files in /var/log/audit exceed unsigned 32 bit values.
Steps to reproduce
- Ensure file system holding /var/log/audit creates inodes with values > 2^32
- Run ausearch with checkpoint option and look at the inode value stored in the checkpoint file verses the actual inode value of the last file used in /var/log/audit
Expected results
The correct inode is stored in the checkpoint file
Actual results
An incorrect inode is stored in the checkpoint file.
- links to
-
RHBA-2024:142993 audit bug fix and enhancement update