Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-83529

[rhel-9] SELinux denials appear when NetworkManager executes ping

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • selinux-policy-38.1.56-1.el9
    • No
    • Moderate
    • 1
    • rhel-security-selinux
    • ssg_security
    • 11
    • 2
    • QE ack
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • SELINUX 250514: 6
    • Release Note Not Required
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      Recently added feature to NetworkManager allowing ping address before it's set [1] causes the following AVCs denials:

      ----
      type=PROCTITLE msg=audit(03/14/2025 09:39:48.688:4336) : proctitle=/usr/bin/ping -I testX4 -c 1 -w 20 192.168.99.1 
      type=SYSCALL msg=audit(03/14/2025 09:39:48.688:4336) : arch=x86_64 syscall=socket success=no exit=EACCES(Permission denied) a0=inet a1=SOCK_DGRAM a2=icmp a3=0x7ffe997db8c0 items=0 ppid=135899 pid=136211 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=ping exe=/usr/bin/ping subj=system_u:system_r:NetworkManager_t:s0 key=(null) 
      type=AVC msg=audit(03/14/2025 09:39:48.688:4336) : avc:  denied  { create } for  pid=136211 comm=ping scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:system_r:NetworkManager_t:s0 tclass=icmp_socket permissive=0 
      ----
      

      [1] https://issues.redhat.com/browse/RHEL-21160

      Found during execution of the following NetworkManager-ci tests:

      connection_ping_ip6_addresses
      connection_ping_ip_addresses_unreachable

      Reproducible: always

      NVRs:
      NetworkManager-1.53.1-1.el9.x86_64
      NetworkManager-libnm-1.53.1-1.el9.x86_64
      NetworkManager-team-1.53.1-1.el9.x86_64
      NetworkManager-tui-1.53.1-1.el9.x86_64
      selinux-policy-38.1.53-2.el9.noarch
      selinux-policy-targeted-38.1.53-2.el9.noarch

              rhn-support-zpytela Zdenek Pytela
              rhn-support-fpokryvk Filip Pokryvka
              Zdenek Pytela Zdenek Pytela
              Milos Malik Milos Malik
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated: