-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2019-7d65c50fd6 2019-10-29 01:27:04.179111 --------------------------------------------------------------------------------
Name : selinux-policy Product : Fedora 31 Version : 3.14.4 Release : 39.fc31 URL : https://github.com/fedora-selinux/selinux-policy Summary : SELinux policy configuration Description : SELinux Base package for SELinux Reference Policy - modular. Based off of reference policy: Checked out revision 2.20091117 -------------------------------------------------------------------------------- Update Information: More info: https://koji.fedoraproject.org/koji/buildinfo?buildID=1404708 ---- More info: https://koji.fedoraproject.org/koji/buildinfo?buildID=1403635 -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 25 2019 Lukas Vrabec <[email protected]> - 3.14.4-39 - Allow confined users to run newaliases - Add interface mysql_dontaudit_rw_db() - Label /var/lib/xfsdump/inventory as amanda_var_lib_t - Allow tmpreaper_t domain to read all domains state - Make httpd_var_lib_t label system mountdir attribute - Update cockpit policy - Allow nagios_script_t domain list files labled sysfs_t. - Allow jetty_t domain search and read cgroup_t files. - Donaudit ifconfig_t domain to read/write mysqld_db_t files - Dontaudit domains read/write leaked pipes * Tue Oct 22 2019 Lukas Vrabec <[email protected]> - 3.14.4-38 - Allow nagios_script_t domain list files labled sysfs_t. - Allow jetty_t domain search and read cgroup_t files. - Allow Gluster mount client to mount files_type - Dontaudit and disallow sys_admin capability for keepalived_t domain - Update numad policy to allow signull, kill, nice and trace processes - Allow ipmievd_t to RW watchdog devices - Update allow rules set for pads_t domain - Allow networkmanager_t domain domain transition to chronyc_t domain BZ(1760226) - Update apache and pkcs policies to make active opencryptoki rules - Allow ldconfig_t domain to manage initrc_tmp_t link files Allow netutils_t domain to write to initrc_tmp_t fifo files - Allow user domains to manage user session services - Allow staff and user users to get status of user systemd session - Update sudo_role_template() to allow caller domain to read syslog pid files -------------------------------------------------------------------------------- References: [ 1 ] Bug #1754219 - SELinux is preventing /usr/sbin/groupadd from read access on the fifo_file fifo_file https://bugzilla.redhat.com/show_bug.cgi?id=1754219 [ 2 ] Bug #1753239 - SELinux is preventing timedatex from 'write' accesses on the directory /etc. https://bugzilla.redhat.com/show_bug.cgi?id=1753239 [ 3 ] Bug #1761765 - Cannot lock down cockpit.service: avc: denied { mounton } / { nnp_transition } https://bugzilla.redhat.com/show_bug.cgi?id=1761765 [ 4 ] Bug #1754397 - SELinux is preventing timedatex from using the 'sys_time' capabilities. https://bugzilla.redhat.com/show_bug.cgi?id=1754397 [ 5 ] Bug #1754800 - SELinux is preventing timedatex from 'execute' accesses on the file /usr/sbin/hwclock. https://bugzilla.redhat.com/show_bug.cgi?id=1754800 [ 6 ] Bug #1755828 - SELinux prevents bitlbee from mmap()-ing the /usr/share/p11-kit/modules/p11-kit-trust.module file https://bugzilla.redhat.com/show_bug.cgi?id=1755828 [ 7 ] Bug #1734188 - SELinux is preventing sssd_be from 'search' accesses on the directory /var/kerberos/krb5. https://bugzilla.redhat.com/show_bug.cgi?id=1734188 [ 8 ] Bug #1715597 - Multiple denials for NetworkManager access to 'nsfs' in Fedora-Rawhide-20190529.n.0 https://bugzilla.redhat.com/show_bug.cgi?id=1715597 [ 9 ] Bug #1701750 - keepalived netlink_connector_socket bind create permission https://bugzilla.redhat.com/show_bug.cgi?id=1701750 [ 10 ] Bug #1699911 - dbus-broker-20-2.fc31 (with systemd-241-4.gitcbf14c9.fc31) triggers some new AVCs making the system not ever finishing boot sequence https://bugzilla.redhat.com/show_bug.cgi?id=1699911 [ 11 ] Bug #1714600 - Mislabeled /dev, causing systemd to cascade crash https://bugzilla.redhat.com/show_bug.cgi?id=1714600 [ 12 ] Bug #1757950 - SELinux prevents opendkim from executing sendmail https://bugzilla.redhat.com/show_bug.cgi?id=1757950 [ 13 ] Bug #1756463 - SELinux is preventing systemd-logind from 'read' accesses on the blk_file mmcblk0p1. https://bugzilla.redhat.com/show_bug.cgi?id=1756463 [ 14 ] Bug #1757043 - SELinux prevents the pads service from starting https://bugzilla.redhat.com/show_bug.cgi?id=1757043 [ 15 ] Bug #1622115 - SELinux is preventing sealert from 'read' accesses on the chr_file random. https://bugzilla.redhat.com/show_bug.cgi?id=1622115 [ 16 ] Bug #1752826 - SELinux is preventing systemd-logind from 'read' accesses on the directory entries. https://bugzilla.redhat.com/show_bug.cgi?id=1752826 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-7d65c50fd6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
