Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-86178

Selinux: NetworkManager is denied to create temporary keyfile

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: Generate New Ti...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Normal Normal
    • rhel-9.7
    • rhel-9.6
    • selinux-policy
    • None
    • selinux-policy-38.1.57-1.el9
    • No
    • Low
    • 1
    • rhel-security-selinux
    • ssg_security
    • 15
    • 1
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • SELINUX 250604: 7
    • Release Note Not Required
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      The following AVC is shown during NetworkManager-ci test no_uuid_in_keyfile_in_usr_lib_dir.

      Affected Versions:

      NetworkManager-1.52.0-1.el9_6.x86_64
      selinux-policy-38.1.53-2.el9.noarch

      ----
      time->Sun Apr 6 06:13:33 2025 type=PROCTITLE msg=audit(1743934413.508:5735): proctitle=2F7573722F7362696E2F4E6574776F726B4D616E61676572002D2D6E6F2D6461656D6F6E type=SYSCALL msg=audit(1743934413.508:5735): arch=c00000b7 syscall=36 success=no exit=-13 a0=aaaab849cbd8 a1=ffffffffffffff9c a2=aaaab8f453f0 a3=c items=0 ppid=1 pid=510435 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="NetworkManager" exe="/usr/sbin/NetworkManager" subj=system_u:system_r:NetworkManager_t:s0 key=(null) type=AVC msg=audit(1743934413.508:5735): avc: denied { create } for pid=510435 comm="NetworkManager" name="e67e0f3e-2f92-366c-a47e-07d1af9c7cbe.nmmeta~" scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:NetworkManager_etc_rw_t:s0 tclass=lnk_file permissive=0 
      ----
      time->Sun Apr 6 06:13:33 2025 type=PROCTITLE msg=audit(1743934413.508:5736): proctitle=2F7573722F7362696E2F4E6574776F726B4D616E61676572002D2D6E6F2D6461656D6F6E type=SYSCALL msg=audit(1743934413.508:5736): arch=c00000b7 syscall=36 success=no exit=-13 a0=aaaab849cbd8 a1=ffffffffffffff9c a2=aaaab8f61000 a3=c items=0 ppid=1 pid=510435 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="NetworkManager" exe="/usr/sbin/NetworkManager" subj=system_u:system_r:NetworkManager_t:s0 key=(null) type=AVC msg=audit(1743934413.508:5736): avc: denied { create } for pid=510435 comm="NetworkManager" name="e67e0f3e-2f92-366c-a47e-07d1af9c7cbe.nmmeta~" scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:NetworkManager_var_run_t:s0 tclass=lnk_file permissive=0

              rhn-support-zpytela Zdenek Pytela
              rhn-support-fpokryvk Filip Pokryvka
              Zdenek Pytela Zdenek Pytela
              Milos Malik Milos Malik
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: