Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-83775

[rhel-10] avc: denied { write } for pid=13733 comm=nft path=/tmp/podman_bats.vMhYNp/podman-kill-fifo.CMSpDDvE0M dev="xvda3" ino=377487601 scontext=unconfined_u:unconfined_r:iptables_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:user_tmp_t:s0

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • No
    • Low
    • 4
    • rhel-security-selinux
    • ssg_security
    • 1
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • SELINUX 250827: 11, SELINUX 250917: 12, SELINUX 251008: 13, SELINUX 251029: 14
    • None
    • None
    • Release Note Not Required
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      What were you trying to do that didn't work?

       

      type=PROCTITLE msg=audit(03/17/25 12:12:47.095:1509) : proctitle=nft -j -f - 
      type=EXECVE msg=audit(03/17/25 12:12:47.095:1509) : argc=4 a0=nft a1=-j a2=-f a3=- 
      type=SYSCALL msg=audit(03/17/25 12:12:47.095:1509) : arch=x86_64 syscall=execve success=yes exit=0 a0=0x7f97e2882d70 a1=0x560887444100 a2=0x7ffdee1af598 a3=0x8 items=0 ppid=13726 pid=13733 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=pts0 ses=16 comm=nft exe=/usr/sbin/nft subj=unconfined_u:unconfined_r:iptables_t:s0-s0:c0.c1023 key=(null) 
      type=AVC msg=audit(03/17/25 12:12:47.095:1509) : avc:  denied  { write } for  pid=13733 comm=nft path=/tmp/podman_bats.vMhYNp/podman-kill-fifo.CMSpDDvE0M dev="xvda3" ino=377487601 scontext=unconfined_u:unconfined_r:iptables_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:user_tmp_t:s0 tclass=fifo_file permissive=0 

       

      Please provide the package NVR for which the bug is seen:

       

      audit-4.0.3-1.el10.x86_64
      selinux-policy-40.13.26-1.el10.noarch 

       

       

      How reproducible is this bug?:

      it seems 100% reproducible

      Steps to reproduce

      1. testing-farm request:
      2. testing-farm request --tag ArtemisUseSpot=false --no-wait --arch x86_64 --environment TMT_SSH_ConnectionAttempts=20 --environment TMT_SSH_ServerAliveCountMax=180 --git-url https://gitlab.com/redhat/centos-stream/tests/kernel/test-plans.git --plan podman/podman --timeout 720 --context component=podman --context distro=rhel-10.0 --context package-name=podman --context stream=ystream --compose RHEL-10.0-20250313.2 --redhat-brew-build 66994279 

      test logs: https://artifacts.osci.redhat.com/testing-farm/8bd44ef7-3b7b-44f7-adb9-119f7d13e4ae/

              rhn-support-zpytela Zdenek Pytela
              bgoncalv@redhat.com Bruno Goncalves
              Zdenek Pytela Zdenek Pytela
              SSG Security QE SSG Security QE
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: