Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-93741

[rhel-9] SELinux denies NetworkManager to kill nft/iptables process

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: Generate New Ti...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Normal Normal
    • rhel-9.7
    • rhel-9.7
    • selinux-policy
    • None
    • selinux-policy-38.1.58-1.el9
    • No
    • Moderate
    • 1
    • rhel-security-selinux
    • ssg_security
    • 17
    • 1
    • QE ack
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • SELINUX 250625: 8
    • Release Note Not Required
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      What were you trying to do that didn't work?

      https://jenkins-networkmanager.apps.ocp.cloud.ci.centos.org/job/NetworkManager-main-c10s/48/artifact/FAIL-report_NetworkManager-ci-M0_Test0122_bond_slb_garp.html#toggle=d77c

      NetworkManager is denied this policy:


      type=PROCTITLE msg=audit(04/09/2025 22:30:34.108:1798) : proctitle=/usr/sbin/NetworkManager --no-daemon
      type=SYSCALL msg=audit(04/09/2025 22:30:34.108:1798) : arch=x86_64 syscall=kill success=no exit=EACCES(Permission denied) a0=0x101d7 a1=SIGTERM a2=0x55ba97228130 a3=0x0 items=0 ppid=1 pid=63397 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=gmain exe=/usr/sbin/NetworkManager subj=system_u:system_r:NetworkManager_t:s0 key=(null)
      type=AVC msg=audit(04/09/2025 22:30:34.108:1798) : avc: denied { signal } for pid=63397 comm=gmain scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=process permissive=0

      Please provide the package NVR for which the bug is seen:

      selinux-policy-38.1.56-1.el9.noarch

      How reproducible is this bug?:

      rarely - this is some race, probably when nft process does not respond in timeout. We have not finished investigation yet.

              rhn-support-zpytela Zdenek Pytela
              rhn-support-fpokryvk Filip Pokryvka
              Zdenek Pytela Zdenek Pytela
              Milos Malik Milos Malik
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: